BACK TO DIRECTORY


Verakta gives any organization — training providers, universities,
event organizers, professional associations — a way to:
- Bulk-upload certificate data via CSV.
- Offer a public verification page where anyone can enter a certificate
number and get an instant, trustworthy confirmation.
Nothing is hardcoded: no institution name, no number format, no interface
text. Everything is configured from the settings page, so a fresh install
is ready to use without touching any code.
Key features
- Bulk import from CSV or Excel (.xlsx) with flexible column mapping,
a preview step before anything is committed, and configurable duplicate
handling (skip, overwrite, or cancel the whole import). Excel date
cells are converted automatically. - Public verification without a page reload (AJAX), with a working
non-JavaScript fallback for accessibility and reliability. - Configurable name privacy: show the full name, a masked name (e.g.
Bu*i Sa****o), or require both the number and the name to match. - Configurable certificate number format: free-form (no validation),
a simple segment-based pattern builder, or a custom regex for unusual
formats. - Native Elementor widget with full styling controls (typography,
colors, border radius, spacing) — plus a Gutenberg block and a
[verakta] shortcode for everywhere else. - Rate limiting per IP and a honeypot field to keep the public
endpoint from being abused. - Audit log recording every import, addition, and edit.
- Translation-ready, shipping with Indonesian and English out of the
box.
Security
Security was treated as a first-class requirement throughout development,
not an afterthought:
- Every database query goes through
$wpdb->prepare()— no SQL string
built by concatenating user input. - All input is sanitized and all output is escaped.
- CSV formula-injection protection on import (cells starting with
=,
+,-, or@are neutralized). - Every admin action is protected by a WordPress nonce and a capability
check. - A dedicated
manage_certificatescapability, so an operator can be
granted access without making them a full Administrator. - Rate limiting and a honeypot field on the public verification endpoint,
with optional trusted-proxy support for sites behind a CDN. - The public AJAX endpoint only ever performs read operations.
- A custom regex number-format pattern is linted for ReDoS risk (nested
quantifiers) both when it’s saved and, as a hard backstop, again at
match time via PCRE2 execution limits. - No connection to any external/third-party service — all verification
logic, rate limiting, and data storage happen entirely on your own
WordPress site.
Screenshots

The public verification page showing a verified result.

The CSV import screen with column mapping and a preview.

The Elementor widget with its styling control panel.
Plugin Details
Active Installs
0Total Downloads
126Version
0.5.0Requires WP
6.0Requires PHP
8.0Tested Up To
7.0.4Added
2026-07-21Last Updated
2026-07-21 9:34am GMTRatings
5
0
4
0
3
0
2
0
1
0