
WP24 Domain Check Security & Risk Analysis
wordpress.org/plugins/wp24-domain-checkCheck (whois) domain names for availability. Easy integration via shortcode or widget.
Is WP24 Domain Check Safe to Use in 2026?
Generally Safe
Score 99/100WP24 Domain Check has a strong security track record. Known vulnerabilities have been patched promptly.
The wp24-domain-check plugin exhibits a mixed security posture, with several concerning areas that overshadow its positive aspects. While the absence of critical or high-severity vulnerabilities in its history and no reported dangerous functions or file operations are strengths, the static analysis reveals significant weaknesses. A large portion of the plugin's attack surface, specifically 4 out of 5 entry points (AJAX handlers), lacks authentication checks, presenting a substantial risk of unauthorized access or manipulation. Furthermore, the high percentage of unsanitized paths identified in the taint analysis, even without critical severity, suggests potential for unexpected behavior or vulnerabilities if inputs are not properly handled. The plugin's vulnerability history, with two medium-severity Cross-Site Scripting (XSS) vulnerabilities, further highlights concerns with input sanitization and output escaping. Although there are no currently unpatched CVEs, the recurrence of XSS issues indicates a need for more robust and consistent input validation and output encoding practices across the codebase. The low percentage of properly escaped output (26%) directly correlates with the historical XSS findings and represents a significant risk.
Key Concerns
- 4 unprotected AJAX handlers
- Low output escaping percentage (26%)
- 3 unsanitized taint flows
- 2 medium CVEs (XSS)
- No nonce checks
- Only 1 capability check on 5 entry points
WP24 Domain Check Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP24 Domain Check <= 1.10.14 - Reflected Cross-Site Scripting
WP24 Domain Check <= 1.6.2 - Cross-Site Scripting
WP24 Domain Check Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP24 Domain Check Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
WP24 Domain Check Maintenance & Trust
Maintenance Signals
Community Trust
WP24 Domain Check Alternatives
Dominion – Domain Checker for WPBakery
dominion-domain-checker-wpbakery-addon
Dominion Domain Checker is a WordPress plugin which allows you to swiftly check domain name availability from your WordPress site.
WHMCS Domain Checker
whmcs-domain-checker
WordPress plugin that allows you to display the responsive WHMCS Domain Checker in a widget.
LJM WHMCS Domain Checker
whmcs-domain-checker-widget
A simple plugin for WordPress that allows you to display the Domain Checker for WHMCS in a nice tidy widget.
Powie's WHOIS Domain Check
powies-whois
Check a Domain WHOIS Lookup for availability. Simple insert the [pwhois] shortcode on a page or post
CB Domain Checker
cb-domain-checker
You can use the plugin for domain name search on your WordPress website using the shortcode [cb-domain-checker]
WP24 Domain Check Developer Profile
1 plugin · 5K total installs
How We Detect WP24 Domain Check
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp24-domain-check/assets/js/domaincheck.js/wp-content/plugins/wp24-domain-check/assets/js/domaincheck.jswp24-domain-check/style.css?ver=wp24-domain-check/assets/js/domaincheck.js?ver=HTML / DOM Fingerprints
wp24-domain-checkwp24dc-wrapper<!-- START WP24 Domain Check SHORTCODE --><!-- END WP24 Domain Check SHORTCODE --><!-- WP24 Domain Check - Available --><!-- WP24 Domain Check - Not Available -->+4 moredata-wp24-domaincheckwp24_domain_check_params/wp-json/wp24-domain-check/v1/check<div class="wp24-domain-check">