
Customize WordPress Emails and Alerts – Better Notifications for WP Security & Risk Analysis
wordpress.org/plugins/bnfwSupercharge your WordPress email notifications using a WYSIWYG editor and shortcodes. Default and new notifications available. Add-ons available.
Is Customize WordPress Emails and Alerts – Better Notifications for WP Safe to Use in 2026?
Generally Safe
Score 99/100Customize WordPress Emails and Alerts – Better Notifications for WP has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "bnfw" v1.9.9.1 demonstrates several positive security practices, including the use of prepared statements for all SQL queries and a robust implementation of nonce and capability checks across its entry points. The absence of unprotected AJAX handlers and REST API routes is commendable, indicating a generally well-secured attack surface. However, the presence of the `unserialize` function is a notable concern, as it can lead to object injection vulnerabilities if not handled with extreme care and strict input validation. While the taint analysis did not reveal critical or high severity issues, one flow with an unsanitized path warrants attention as it represents a potential avenue for exploitation.
The vulnerability history reveals two past medium severity CVEs, specifically related to Cross-Site Request Forgery (CSRF) and Exposure of Sensitive Information. The fact that there are no currently unpatched vulnerabilities is a positive sign, suggesting that the developers are responsive to security issues. However, the recurring nature of these vulnerability types in the past indicates a potential weakness in input sanitization and authorization logic that needs ongoing vigilance. Overall, the plugin has a decent security posture with good foundational practices, but the identified risks, particularly around `unserialize` and past vulnerability patterns, require careful monitoring and potential mitigation.
Key Concerns
- Dangerous function unserialize detected
- Flow with unsanitized path in taint analysis
- Previous medium severity CVEs (2)
Customize WordPress Emails and Alerts – Better Notifications for WP Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Better Notifications for WP <= 1.9.2 - Cross-Site Request Forgery via handle_actions
Better Notifications for WP <= 1.8.6 - Email Address Disclosure
Customize WordPress Emails and Alerts – Better Notifications for WP Release Timeline
Customize WordPress Emails and Alerts – Better Notifications for WP Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Customize WordPress Emails and Alerts – Better Notifications for WP Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 93
Maintenance & Trust
Customize WordPress Emails and Alerts – Better Notifications for WP Maintenance & Trust
Maintenance Signals
Community Trust
Customize WordPress Emails and Alerts – Better Notifications for WP Alternatives
Notification – Custom Notifications and Alerts for WordPress
notification
Take full control of WordPress emails and notifications. Replace default messages, add custom triggers, and send alerts via email, webhook, Slack, and …
Get Notified
get-notified
Get Notified is a simple to use notification plugin that notifies you of certain WordPress events.
Email Notification on Login
email-notification-on-login
Receive an email after each successful login with the user information
Simple Login Notification
simple-login-notification
Sends a notification email when admins and other users log in to your site.
Post Status Notifier Lite
post-status-notifier-lite
Notify on every post change: Flexible rules, custom placeholders and support for all post types and taxonomies.
Customize WordPress Emails and Alerts – Better Notifications for WP Developer Profile
2 plugins · 30K total installs
How We Detect Customize WordPress Emails and Alerts – Better Notifications for WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bnfw/assets/css/admin-styles.css/wp-content/plugins/bnfw/assets/css/common.css/wp-content/plugins/bnfw/assets/js/admin-script.js/wp-content/plugins/bnfw/assets/js/editor-script.js/wp-content/plugins/bnfw/assets/js/select2/select2.min.js/wp-content/plugins/bnfw/assets/js/select2/select2.css/wp-content/plugins/bnfw/assets/js/tinymce/tinymce.min.js/wp-content/plugins/bnfw/assets/js/tinymce/themes/modern/theme.min.js+46 more/wp-content/plugins/bnfw/assets/js/admin-script.js/wp-content/plugins/bnfw/assets/js/editor-script.js/wp-content/plugins/bnfw/assets/js/select2/select2.min.js/wp-content/plugins/bnfw/assets/js/tinymce/tinymce.min.js/wp-content/plugins/bnfw/assets/js/tinymce/themes/modern/theme.min.js/wp-content/plugins/bnfw/assets/js/tinymce/plugins/textcolor/plugin.min.js+45 moreHTML / DOM Fingerprints
bnfw-notification-metabnfw_admin_scripttinymce