Barbas – Default wp mail sender Security & Risk Analysis

wordpress.org/plugins/barbas-default-wp-mail-sender

Simple way to change the default wordpress sender\'s name and email.

10 active installs v2.0 PHP 5.6+ WP 4.9+ Updated Nov 20, 2023
change-from-email-and-namechange-from-wordpress-email-namechange-mail-sender-emailchange-mail-sender-namewordpress-default-mail-sender-change
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Barbas – Default wp mail sender Safe to Use in 2026?

Generally Safe

Score 85/100

Barbas – Default wp mail sender has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

Based on the static analysis, the "barbas-default-wp-mail-sender" plugin v2.0 presents a generally strong security posture. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate a lack of dangerous functions, all SQL queries utilizing prepared statements, no file operations, and no external HTTP requests. This demonstrates a conscientious approach to secure coding practices.

However, there are areas that warrant attention. The low percentage of properly escaped output (38%) is a concern, as it suggests potential vulnerabilities to cross-site scripting (XSS) attacks if user-supplied data is displayed without adequate sanitization. The lack of nonce checks and capability checks on any potential entry points (though none were found in this analysis) also leaves room for potential unauthorized actions if new entry points are introduced in future versions without proper security measures. The absence of any recorded vulnerability history is a positive sign, suggesting a history of secure development, but it does not negate the risks identified in the current static analysis.

In conclusion, while the plugin has a very small attack surface and good practices regarding SQL and external requests, the unescaped output is a notable weakness. The lack of any found vulnerabilities historically is a good indicator, but the current code has a specific area for improvement concerning output escaping. Future development should prioritize addressing the output escaping issue and maintaining the minimal attack surface.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Barbas – Default wp mail sender Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Barbas – Default wp mail sender Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

38% escaped8 total outputs
Attack Surface

Barbas – Default wp mail sender Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actioninitbarbas-dwms.php:25
actionadmin_initbarbas-dwms.php:26
actionadmin_menubarbas-dwms.php:27
filterwp_mail_frombarbas-dwms.php:28
filterwp_mail_from_namebarbas-dwms.php:29
actioninitincludes\barbas-functions.php:6
actionadmin_noticesincludes\barbas-functions.php:13
actionadmin_initincludes\barbas-functions.php:23
actionadmin_initincludes\barbas-functions.php:57
actionadmin_menuincludes\barbas-functions.php:116
filterwp_mail_fromincludes\barbas-functions.php:149
filterwp_mail_from_nameincludes\barbas-functions.php:162
Maintenance & Trust

Barbas – Default wp mail sender Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedNov 20, 2023
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Barbas – Default wp mail sender Developer Profile

Guilherme Souza

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Barbas – Default wp mail sender

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Barbas – Default wp mail sender