WP Lawyer Security & Risk Analysis

wordpress.org/plugins/wp-lawyer

WP-Lawyer is a custom WordPress plugin for Lawyers and Law Firms which use WordPress.

30 active installs v1.0.4 PHP + WP 4.7+ Updated Jan 5, 2025
attorneyslaw-firmlawyers
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Lawyer Safe to Use in 2026?

Generally Safe

Score 92/100

WP Lawyer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The wp-lawyer plugin version 1.0.4 presents a generally good security posture based on the provided static analysis. The plugin has a remarkably small attack surface, with no apparent AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential for external exploitation. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is a strong positive indicator. The use of prepared statements for all SQL queries and the presence of nonce and capability checks also suggest a developer who is aware of common WordPress security best practices.

However, a significant concern arises from the output escaping. With 63 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that is not properly escaped can be manipulated by an attacker to inject malicious scripts. The lack of any recorded vulnerability history is a positive sign, but it does not negate the clear risk identified in the output escaping. This means that while the plugin hasn't had historical issues, it currently has a significant, unaddressed security flaw that could be exploited.

In conclusion, the plugin demonstrates strengths in minimizing its attack surface and implementing fundamental security checks like prepared statements and nonces. However, the complete lack of output escaping is a critical weakness that requires immediate attention. Until this is rectified, the plugin should be considered to have a moderate to high security risk due to the potential for XSS attacks.

Key Concerns

  • 0% of outputs properly escaped (XSS risk)
Vulnerabilities
None known

WP Lawyer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Lawyer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
63
0 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped63 total outputs
Attack Surface

WP Lawyer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actioninitmodules\attorneys.php:60
actioninitmodules\attorneys.php:107
actioninitmodules\attorneys.php:152
actioninitmodules\attorneys.php:197
actioninitmodules\attorneys.php:241
actioninitmodules\attorneys.php:287
actioninitmodules\attorneys.php:332
actioninitmodules\attorneys.php:377
actioninitmodules\attorneys.php:421
actioninitmodules\attorneys.php:466
actionadmin_menumodules\attorneys.php:558
actionsave_postmodules\attorneys.php:610
filtertemplate_includemodules\attorneys.php:909
actioninitmodules\cases.php:60
actioninitmodules\cases.php:107
actioninitmodules\cases.php:157
actioninitmodules\cases.php:201
actionadmin_menumodules\cases.php:240
actionsave_postmodules\cases.php:286
filtertemplate_includemodules\cases.php:366
actionwp_enqueue_scriptswp-lawyer.php:76
Maintenance & Trust

WP Lawyer Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 5, 2025
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

WP Lawyer Developer Profile

Brandon Hubbard

4 plugins · 90 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Lawyer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-lawyer/assets/css/main.css
Version Parameters
wp-lawyer/assets/css/main.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP Lawyer