
Birthday Emails Security & Risk Analysis
wordpress.org/plugins/birthday-emailsAutomatically send an email to WordPress or BuddyPress users on their birthday.
Is Birthday Emails Safe to Use in 2026?
Generally Safe
Score 85/100Birthday Emails has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "birthday-emails" plugin v1.2.3 presents a mixed security posture. On the positive side, it has no known historical vulnerabilities and implements nonces and capability checks for its code. The absence of dangerous functions, file operations, and external HTTP requests is also reassuring. However, the static analysis reveals several areas of concern. A significant portion of SQL queries are not using prepared statements, which could lead to SQL injection vulnerabilities if the inputs are not properly sanitized. Additionally, the taint analysis identified a flow with an unsanitized path, which is a critical risk, even if it's not classified as critical severity, as it indicates a potential for data manipulation or unauthorized access. The output escaping is also notably low, with less than half of outputs properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities.
Key Concerns
- Flows with unsanitized paths
- SQL queries without prepared statements
- Low percentage of properly escaped output
Birthday Emails Security Vulnerabilities
Birthday Emails Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Birthday Emails Attack Surface
WordPress Hooks 15
Scheduled Events 1
Maintenance & Trust
Birthday Emails Maintenance & Trust
Maintenance Signals
Community Trust
Birthday Emails Alternatives
Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin
ultimate-member
Membership & community plugin with user profiles, registration & login, member directories, content restriction, user roles and much more.
Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress
wp-user-avatar
Setup paid membership, accept payment, sell subscription & digital product, paywall, create login & registration form, user profile & member directory
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
user-registration
Build membership sites with tiered plans, content restriction, drag-&-drop custom registration & login form builder, and built-in payment system.
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages
convertkit
Build your email subscriber lists, send email marketing newsletters, sell more products and build your membership site with Kit (formerly ConvertKit).
Ultimate Member – reCAPTCHA
um-recaptcha
Stop bots on your registration & login forms with Google reCAPTCHA
Birthday Emails Developer Profile
1 plugin · 300 total installs
How We Detect Birthday Emails
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/birthday-emails/css/style.css/wp-content/plugins/birthday-emails/js/birthday_emails.js/wp-content/plugins/birthday-emails/js/birthday_emails.jsbirthday-emails/css/style.css?ver=birthday-emails/js/birthday_emails.js?ver=HTML / DOM Fingerprints
cjl_bdemail_settings_wrapdata-cjl-bdemail-iddata-cjl-bdemail-datecjl_bdemails_settings