WP Insurance – WordPress Insurance Service Plugin Security & Risk Analysis

wordpress.org/plugins/wp-insurance

WP Insurance is a Service WordPress plugin.

100 active installs v2.1.4 PHP + WP 5.0+ Updated Dec 4, 2025
agencyinsuranceinsurance-plugininsurance-service-pluginservices
100
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 28, 2023
Safety Verdict

Is WP Insurance – WordPress Insurance Service Plugin Safe to Use in 2026?

Generally Safe

Score 100/100

WP Insurance – WordPress Insurance Service Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 28, 2023Updated 4mo ago
Risk Assessment

The wp-insurance plugin version 2.1.4 exhibits a generally good security posture, primarily due to its adherence to several key security practices. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and the presence of nonce and capability checks are positive indicators. The plugin also demonstrates a commitment to output escaping, although the 60% proper escaping rate leaves room for improvement and potential vulnerabilities.

The static analysis reveals a small attack surface, with only one shortcode identified as an entry point. Crucially, none of the entry points are reported as unprotected, suggesting that access controls are likely in place. The lack of identified taint flows and dangerous functions further strengthens the perception of a secure codebase. However, the 60% output escaping rate is a notable concern. While not explicitly flagged as a vulnerability in this analysis, a significant portion of output is not properly escaped, which could be exploited for Cross-Site Scripting (XSS) if user-supplied data is rendered directly.

The vulnerability history indicates one past medium-severity CVE, specifically related to Cross-Site Request Forgery (CSRF). The fact that this vulnerability is currently unpatched and the last one was relatively recent (February 2023) suggests a pattern of past security issues that were addressed, but it also highlights that the plugin is not immune to vulnerabilities. The absence of unpatched CVEs at the time of analysis is a positive sign, but the historical trend warrants continued vigilance.

Key Concerns

  • 60% output escaping rate
  • Past medium CVE (CSRF)
Vulnerabilities
1

WP Insurance – WordPress Insurance Service Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-0501medium · 4.3Cross-Site Request Forgery (CSRF)

WP Insurance – WordPress Insurance Service Plugin <= 2.1.3 - Cross-Site Request Forgery leading to Arbitrary Plugin Activation

Feb 28, 2023 Patched in 2.1.4 (329d)
Code Analysis
Analyzed Mar 16, 2026

WP Insurance – WordPress Insurance Service Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
94
141 escaped
Nonce Checks
1
Capability Checks
5
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped235 total outputs
Attack Surface

WP Insurance – WordPress Insurance Service Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wp_insurance] admin\wpinsurance_shortcode.php:85
WordPress Hooks 28
actionadmin_menuadmin\admin-init.php:17
actionadmin_enqueue_scriptsadmin\admin-init.php:41
actionadmin_enqueue_scriptsadmin\class.settings-api.php:30
actionadmin_initadmin\plugin-options.php:18
actionadmin_menuadmin\plugin-options.php:19
actionadmin_menuadmin\Recommended_Plugins.php:78
actionadmin_enqueue_scriptsadmin\Recommended_Plugins.php:79
filtercmb2_initadmin\wpinsurance_custom-metabox.php:5
actioninitadmin\wpinsurance_custom-post-type.php:239
actionelementor/initincludes\helper-function.php:20
actionelementor/widgets/registerinit.php:11
actionelementor/widgets/widgets_registeredinit.php:13
actionwp_enqueue_scriptsinit.php:74
actioninitinit.php:96
actioninitinit.php:105
filterregister_post_type_argsinit.php:154
filtersingle_templatewpinsurance.php:26
filterarchive_templatewpinsurance.php:43
filtersingle_templatewpinsurance.php:62
actionadmin_initwpinsurance.php:131
actionadmin_noticeswpinsurance.php:158
filterviews_edit-wpinsurancewpinsurance.php:221
actionwpinsurance_category_pre_add_formwpinsurance.php:222
filterviews_edit-wpinsurance_agentwpinsurance.php:282
actionwpinsurance_agent_cat_pre_add_formwpinsurance.php:283
filterviews_edit-wpinsurance_gallerywpinsurance.php:341
actionwpinsurance_gallery_cat_pre_add_formwpinsurance.php:342
actionwsa_form_bottom_pro_themeswpinsurance.php:345
Maintenance & Trust

WP Insurance – WordPress Insurance Service Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

WP Insurance – WordPress Insurance Service Plugin Developer Profile

DevItems

13 plugins · 179K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
93 days
View full developer profile
Detection Fingerprints

How We Detect WP Insurance – WordPress Insurance Service Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-insurance/assets/css/frontend.css/wp-content/plugins/wp-insurance/assets/css/custom.css/wp-content/plugins/wp-insurance/assets/js/frontend.js/wp-content/plugins/wp-insurance/assets/js/custom.js
Script Paths
/wp-content/plugins/wp-insurance/assets/js/frontend.js/wp-content/plugins/wp-insurance/assets/js/custom.js
Version Parameters
wp-insurance/assets/css/frontend.css?ver=wp-insurance/assets/css/custom.css?ver=wp-insurance/assets/js/frontend.js?ver=wp-insurance/assets/js/custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpinsurance-service-singlewpinsurance-archive-itemwpinsurance-agent-singlelp-nav-tab-wrapper
HTML Comments
Checks for single template by post typeChecks for archive template by post typeGet the value of a settings fieldCheck Plugins is Installed or not+4 more
Data Attributes
data-post-type="wpinsurance"data-post-type="wpinsurance_agent"
FAQ

Frequently Asked Questions about WP Insurance – WordPress Insurance Service Plugin