Watermark PDF for WordPress and WooCommerce Security & Risk Analysis

wordpress.org/plugins/watermark-pdf

Watermark PDF for WordPress and WooCommerce is an easy-to-use plugin that lets you add text and image watermarks to PDF files to protect them from una …

80 active installs v1.0.6 PHP 7.1.3+ WP 5.3.0+ Updated Jan 28, 2026
pdfsecuritystampwatermarkwordpress
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Watermark PDF for WordPress and WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Watermark PDF for WordPress and WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "watermark-pdf" plugin v1.0.6 exhibits a strong security posture based on the provided static analysis. The plugin has no known vulnerabilities, a clean history, and the code analysis reveals excellent practices. Specifically, the absence of dangerous functions, the use of prepared statements for all SQL queries, and a high percentage of properly escaped output are significant strengths. Furthermore, the presence of nonce and capability checks on its single AJAX entry point indicates an effort to secure its attack surface. The plugin does not perform external HTTP requests, which further reduces its potential for remote code execution or data exfiltration.

While the static analysis shows no critical or high-severity issues, and the taint analysis found no unsanitized paths, it's important to acknowledge potential areas for improvement. The analysis of file operations (8 instances) and bundled libraries (Select2, TCPDF) could be further scrutinized. Although no specific vulnerabilities are indicated, outdated or insecure versions of bundled libraries can become attack vectors. The absence of taint analysis flows being analyzed is not a weakness but rather an indicator that the tool may not have been configured to perform this deep dive, or that the code structure simply didn't present obvious tainted data flows.

Overall, "watermark-pdf" v1.0.6 appears to be a well-developed and secure plugin. Its proactive approach to security, evident in its coding practices and lack of historical vulnerabilities, is commendable. The plugin's attack surface is minimal and appears to be protected. The main recommendation would be to ensure that bundled libraries are regularly updated to mitigate any potential future risks associated with them.

Vulnerabilities
None known

Watermark PDF for WordPress and WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Watermark PDF for WordPress and WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
512 escaped
Nonce Checks
3
Capability Checks
1
File Operations
8
External Requests
0
Bundled Libraries
2

Bundled Libraries

Select2TCPDF

Output Escaping

98% escaped524 total outputs
Attack Surface

Watermark PDF for WordPress and WooCommerce Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_get_pdf_dimensionsincludes\class-pdf-watermark.php:196
WordPress Hooks 11
actionadmin_enqueue_scriptscore\core.php:84
actionplugins_loadedgpls-wmpdf-watermark-pdf.php:260
filterwp_get_attachment_urlincludes\class-pdf-watermark.php:192
filterwp_get_attachment_image_srcincludes\class-pdf-watermark.php:193
filterimage_make_intermediate_sizeincludes\class-pdf-watermark.php:194
filterimage_resize_dimensionsincludes\class-pdf-watermark.php:195
actionadmin_enqueue_scriptsincludes\class-single-apply-watermarks.php:40
actiondelete_expired_transientsincludes\class-watermark-base.php:74
actionadmin_headincludes\class-watermarks-templates.php:153
actionadmin_menuincludes\Settings.php:92
actionadmin_enqueue_scriptsincludes\Settings.php:93
Maintenance & Trust

Watermark PDF for WordPress and WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 28, 2026
PHP min version7.1.3
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

Watermark PDF for WordPress and WooCommerce Developer Profile

GrandPlugins

20 plugins · 9K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
160 days
View full developer profile
Detection Fingerprints

How We Detect Watermark PDF for WordPress and WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/watermark-pdf/assets/css/free/style.css/wp-content/plugins/watermark-pdf/assets/js/free/script.js/wp-content/plugins/watermark-pdf/assets/js/free/admin-script.js/wp-content/plugins/watermark-pdf/assets/js/admin/watermark-pdf-admin.js
Script Paths
/wp-content/plugins/watermark-pdf/assets/js/free/script.js/wp-content/plugins/watermark-pdf/assets/js/free/admin-script.js/wp-content/plugins/watermark-pdf/assets/js/admin/watermark-pdf-admin.js
Version Parameters
watermark-pdf/assets/css/free/style.css?ver=watermark-pdf/assets/js/free/script.js?ver=watermark-pdf/assets/js/free/admin-script.js?ver=watermark-pdf/assets/js/admin/watermark-pdf-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
gpls-wmpdf-admin-wrap
Data Attributes
data-gpls-wmpdf-options
JS Globals
gpls_wmpdf_localize_data
FAQ

Frequently Asked Questions about Watermark PDF for WordPress and WooCommerce