
ValidateCertify Free Security & Risk Analysis
wordpress.org/plugins/validar-certificados-de-cursosValidateCertify is the ultimate plugin for ensuring the authenticity and integrity of issued certificates.
Is ValidateCertify Free Safe to Use in 2026?
Mostly Safe
Score 77/100ValidateCertify Free is generally safe to use. 2 past CVEs were resolved. Keep it updated.
The plugin 'validar-certificados-de-cursos' v1.6.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for a majority of its SQL queries and implementing nonce and capability checks for its limited entry points. The absence of file operations and external HTTP requests further reduces its attack surface. However, concerns arise from the taint analysis, which identified three high-severity flows with unsanitized paths. While the total attack surface is small, these unsanitized paths represent potential risks that could be exploited if an attacker can control the input leading to these flows.
The vulnerability history reveals a concerning pattern. The plugin has two known CVEs, with one remaining unpatched. Both past vulnerabilities were of medium severity, indicating a recurring tendency for security weaknesses to emerge. The recent CVE in 2025 suggests ongoing issues. The history of medium-severity vulnerabilities, combined with the high-severity taint flows, suggests that while the plugin developers are making some efforts towards security, there are critical areas that require immediate attention to prevent exploitation. The lack of critical and high severity vulnerabilities in the past is encouraging, but the presence of unpatched issues and concerning taint flows necessitates caution.
Key Concerns
- Unpatched CVE found
- High severity unsanitized taint flows
- Medium severity unpatched CVEs (cumulative)
- Output escaping is not fully proper (77%)
ValidateCertify Free Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
ValidateCertify <= 1.6.2 - Cross-Site Request Forgery
ValidateCertify <= 1.6.1 - Cross-Site Request Forgery
ValidateCertify Free Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ValidateCertify Free Attack Surface
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
ValidateCertify Free Maintenance & Trust
Maintenance Signals
Community Trust
ValidateCertify Free Alternatives
Accredible Certificates & Open Badges
accredible-certificates
Certificates, open badges and blockchain credentials. Create, update and manage them on your Wordpress site.
PW WooCommerce Gift Cards
pw-woocommerce-gift-cards
Sell gift cards to your WooCommerce store, in just a few minutes!
Ultimate Gift Cards for WooCommerce
woo-gift-cards-lite
Create, sell and manage WooCommerce gift cards to attract more sales and multiply your revenue at your online store.
Gift Up Gift Cards for WordPress and WooCommerce
gift-up
The simplest way to sell gift cards online. Sell your own gift cards, gift certificates and gift vouchers from inside your WordPress website easily wi …
Sensei LMS Certificates
sensei-certificates
Award your students with a certificate of completion and a sense of accomplishment after finishing a course.
ValidateCertify Free Developer Profile
1 plugin · 1K total installs
How We Detect ValidateCertify Free
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/validar-certificados-de-cursos/assets/css/validatecertify-styles.cssvalidar-certificados-de-cursos/assets/css/validatecertify-styles.css?ver=HTML / DOM Fingerprints
custom-dashboard-widget-stvc<!-- ValidateCertify Free Admin Dashboard ValidateCertify Free ShortCode<h>Access your tools</h><p>Add a certificate.</p><a href="" class="button button-primary">Add Certificate</a>