
Privacy Policy Generator – WPLP Legal Pages Security & Risk Analysis
wordpress.org/plugins/wplegalpagesCreate and manage legal pages for WordPress websites using ready-made policy templates that support common privacy and compliance requirements.
Is Privacy Policy Generator – WPLP Legal Pages Safe to Use in 2026?
Generally Safe
Score 92/100Privacy Policy Generator – WPLP Legal Pages has a strong security track record. Known vulnerabilities have been patched promptly.
The wplegalpages plugin exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices with a high percentage of prepared SQL statements and properly escaped output. The presence of numerous nonce and capability checks also suggests an awareness of security principles. However, a significant concern arises from the substantial attack surface exposed through 18 unprotected AJAX handlers. This lack of authentication on a considerable number of entry points presents a prime opportunity for attackers to trigger unintended actions or exploit vulnerabilities. Furthermore, the static analysis flagged two flows with unsanitized paths, one of high severity, which could potentially lead to code execution or data manipulation if not properly mitigated. The plugin's vulnerability history, with a significant number of medium and one high severity CVEs, particularly those related to missing authorization and cross-site scripting, reinforces the risks associated with unprotected entry points and input handling. While there are no currently unpatched CVEs, this history indicates a recurring pattern of vulnerabilities that, if not actively managed, could resurface.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flow
- Flows with unsanitized paths
- 1 high severity CVE in history
- 6 medium severity CVEs in history
- Dangerous function: unserialize
Privacy Policy Generator – WPLP Legal Pages Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
WPLegalPages <= 3.5.4 - Missing Authorization
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.5.1 - Missing Authorization to Unauthenticated API Disconnect
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.4.3 - Missing Authorization to Authenticated (Contributor+) Arbitrary Plugin Installation
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages <= 3.2.7 - Cross-Site Request Forgery
WPLegalPages <= 2.9.2 - Authenticated (Author+) Stored Cross-Site Scripting via Shortcode
Privacy Policy Generator, Terms & Conditions Generator - WPLegalPages <= 2.7.0 - Arbitrary Settings Update to Stored Cross-Site Scripting
Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WPLegalPages < 1.1 - Cross-Site Scripting
Privacy Policy Generator – WPLP Legal Pages Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Privacy Policy Generator – WPLP Legal Pages Attack Surface
AJAX Handlers 24
REST API Routes 7
Shortcodes 3
WordPress Hooks 64
Maintenance & Trust
Privacy Policy Generator – WPLP Legal Pages Maintenance & Trust
Maintenance Signals
Community Trust
Privacy Policy Generator – WPLP Legal Pages Alternatives
iubenda | All-in-one Compliance for GDPR / CCPA Cookie Consent + more
iubenda-cookie-law-solution
The solution for GDPR compliance + more. Get your cookie banner, privacy policy, terms and conditions and handle cookie consent in just one plugin.
TermsFeed AutoTerms: Privacy Policy Generator, Cookie Consent, GDPR, CCPA, Terms & Conditions, Disclaimers, Cookies Policy, EULA
auto-terms-of-service-and-privacy-policy
All-in-One compliance solution from TermsFeed: Generator of Privacy Policy, T&Cs, Affiliate Disclaimers and Cookie Consent Notice Banner.
Legal Pages – Privacy Policy, Terms & Conditions, GDPR, CCPA, and Cookie Notice Generator
legal-pages
The best WordPress legal pages generator that comes with pre-made templates for GDPR, CCPA, DMCA, Privacy Policy, Terms & Conditions, Cookie Polic …
Usercentrics Privacy Policy Generator
privacy-policy-usercentrics
Generate GDPR, CCPA & global privacy and cookie policies automatically. Stay compliant, build trust, and save time with Usercentrics.
Cookie Notice & Compliance for GDPR / CCPA
cookie-notice
Cookie Notice allows you to you elegantly inform users that your site uses cookies and helps you comply with GDPR, CCPA and other data privacy laws.
Privacy Policy Generator – WPLP Legal Pages Developer Profile
2 plugins · 20K total installs
How We Detect Privacy Policy Generator – WPLP Legal Pages
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wplegalpages/admin/js/script.js/wp-content/plugins/wplegalpages/admin/css/style.css/wp-content/plugins/wplegalpages/admin/css/admin-style.css/wp-content/plugins/wplegalpages/admin/css/bootstrap.css/wp-content/plugins/wplegalpages/assets/css/wplegalpages-custom.css/wp-content/plugins/wplegalpages/assets/js/wplegalpages-custom.js/wp-content/plugins/wplegalpages/admin/js/script.js/wp-content/plugins/wplegalpages/admin/js/tinymce/tinymce.min.js/wp-content/plugins/wplegalpages/admin/js/tinymce/plugins/wplegalpages_shortcodes.js/wp-content/plugins/wplegalpages/admin/js/admin.js/wp-content/plugins/wplegalpages/assets/js/frontend.jswplegalpages/admin/css/style.css?ver=wplegalpages/admin/css/admin-style.css?ver=wplegalpages/admin/css/bootstrap.css?ver=wplegalpages/admin/js/script.js?ver=wplegalpages/admin/js/admin.js?ver=wplegalpages/assets/css/wplegalpages-custom.css?ver=wplegalpages/assets/js/wplegalpages-custom.js?ver=wplegalpages/assets/js/frontend.js?ver=HTML / DOM Fingerprints
wplegalpages-pro-promotionwplegalpages-shortcode-generatorwplegalpages-page-builder-wrapperwplegalpages-add-new-page-form<!-- If this file is called directly, abort. --><!-- Provide a admin area view for the settings. --><!-- This file is used to markup the admin-facing aspects of the plugin. --><!-- Upgrade to Pro -->+13 moredata-lp-iddata-lp-typedata-lp-slugdata-lp-templatewplegalpages_global_varsWPLP_LITE_PLUGIN_URLWPLP_CUSTOM_CSS_MAX_LENwplegalpages_admin_script_varstinymce_wplegalpages_shortcodes_config/wp-json/wplegal/v2/[wplegalpages_shortcode][wplegalpages_generator]