
Trusty Whistleblowing Solution Security & Risk Analysis
wordpress.org/plugins/trusty-whistleblowing-solutionTrusty is an instantly available, customizable and secure web-based whistleblowing solution developed by compliance experts.
Is Trusty Whistleblowing Solution Safe to Use in 2026?
Mostly Safe
Score 78/100Trusty Whistleblowing Solution is generally safe to use. 1 past CVE were resolved. Keep it updated.
The trusty-whistleblowing-solution plugin exhibits a concerning security posture primarily due to its substantial attack surface lacking proper authorization checks. All four identified AJAX entry points are unprotected, representing a significant risk. While the plugin demonstrates good practices in SQL query handling with 100% prepared statements and a high rate of output escaping (83%), the absence of nonce and capability checks on its AJAX handlers is a critical oversight. The taint analysis reveals two flows with unsanitized paths, though no critical or high severity issues were identified in this specific analysis, suggesting potential for vulnerabilities if these paths are exploitable.
The vulnerability history, particularly the single medium-severity CVE marked as currently unpatched and a pattern of "Missing Authorization" vulnerabilities, strongly indicates a recurring weakness in how the plugin handles user permissions and access control. This history, combined with the static analysis findings, suggests a fundamental issue with securing entry points. While the plugin has strengths in its database interactions and output handling, the critical lack of authorization on its primary interaction points and a history of similar vulnerabilities paint a picture of a plugin that requires immediate attention to mitigate potential exploits.
Key Concerns
- Unprotected AJAX handlers
- Missing nonce checks
- Missing capability checks
- Unpatched CVE (medium severity)
- Flows with unsanitized paths
Trusty Whistleblowing Solution Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Trusty Whistleblowing <= 1.5.2 - Missing Authorization
Trusty Whistleblowing Solution Code Analysis
Output Escaping
Data Flow Analysis
Trusty Whistleblowing Solution Attack Surface
AJAX Handlers 4
WordPress Hooks 4
Maintenance & Trust
Trusty Whistleblowing Solution Maintenance & Trust
Maintenance Signals
Community Trust
Trusty Whistleblowing Solution Alternatives
Whistleblowing & Contact Form – Secure, Anonymous, Drag & Drop Builder
whistleblowing-system
Create anonymous whistleblowing or standard contact forms with free conditional logic and secure two-way messaging. GDPR-compliant and responsive.
ANON::form embedded secure form
anonform-embedded-secure-form
Embed ANON::form's End-to-End Encrypted secure and anonymized web forms into your website with an iframe and a shortcode.
Trusty Whistleblowing Solution Developer Profile
1 plugin · 500 total installs
How We Detect Trusty Whistleblowing Solution
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tr-free-whistleblowing-solution/public/css/tr-free-whistleblowing-solution-public.css/wp-content/plugins/tr-free-whistleblowing-solution/public/js/tr-free-whistleblowing-solution-public.js/wp-content/plugins/tr-free-whistleblowing-solution/public/js/tr-free-whistleblowing-solution-public.jstr-free-whistleblowing-solution-public.css?ver=tr-free-whistleblowing-solution-public.js?ver=