Casper’s Leave Notice Security & Risk Analysis

wordpress.org/plugins/caspers-leave-notice

A quick, easy way to notify your users when they are leaving your site. You can edit the content and add domain exclusions.

200 active installs v1.2.3 PHP + WP 4.0+ Updated Jul 18, 2019
exit-warningexternal-linksleaving-notificationpop-up-disclaimersite-abandonment-notice
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Casper’s Leave Notice Safe to Use in 2026?

Generally Safe

Score 85/100

Casper’s Leave Notice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The caspers-leave-notice plugin v1.2.3 exhibits a generally strong security posture in several key areas. The absence of known vulnerabilities (CVEs) and the lack of any critical or high-severity taint flows are positive indicators. Furthermore, the plugin's entry points (AJAX handlers, REST API routes, shortcodes, cron events) are all reported as protected, which is excellent. The plugin also avoids potentially risky operations like file operations and external HTTP requests.

However, a significant concern arises from the output escaping. With 9 total outputs and 0% properly escaped, this presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from or is processed by the plugin without proper sanitization could be manipulated to inject malicious scripts. The complete lack of capability checks, while not directly a vulnerability in itself, means that access controls are not being enforced at the plugin level, relying entirely on WordPress's core roles and permissions. This could be problematic if certain functionalities are intended for specific user roles only.

In conclusion, while the plugin's attack surface is well-managed and it has a clean vulnerability history, the pervasive issue with output escaping is a critical weakness that requires immediate attention. This oversight could easily lead to exploitable XSS flaws. Addressing the output escaping is paramount to improving the plugin's security.

Key Concerns

  • 0% output escaping
  • 0 capability checks
Vulnerabilities
None known

Casper’s Leave Notice Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Casper’s Leave Notice Release Timeline

v1.2.2
v1.2.1
v1.2
v1.1
v1.0.1
Code Analysis
Analyzed Mar 16, 2026

Casper’s Leave Notice Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped9 total outputs
Attack Surface

Casper’s Leave Notice Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionwp_footercaspers-leave-notice.php:81
actionwp_footercaspers-leave-notice.php:105
actionadmin_menufunctions\admin\admin-page.php:12
actionadmin_initfunctions\options.php:45
actionadmin_initfunctions\options.php:88
actionadmin_initfunctions\options.php:130
actionwp_enqueue_scriptsfunctions\scripts-and-support.php:7
actionwp_enqueue_scriptsfunctions\scripts-and-support.php:14
filterplugin_action_linksfunctions\scripts-and-support.php:17
Maintenance & Trust

Casper’s Leave Notice Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJul 18, 2019
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings5
Active installs200
Developer Profile

Casper’s Leave Notice Developer Profile

XAce90

2 plugins · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Casper’s Leave Notice

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/caspers-leave-notice/caspers-leave-notice.css
Script Paths
/wp-content/plugins/caspers-leave-notice/caspers-leave-notice.js
Version Parameters
caspers-leave-notice/caspers-leave-notice.css?ver=caspers-leave-notice/caspers-leave-notice.js?ver=

HTML / DOM Fingerprints

CSS Classes
cpln-leavenoticecpln-positioncpln-overlaycpln-tbcpln-tdcpln-contentcpln-redirect-boxcpln-redirect-box__content+6 more
Data Attributes
data-start-time
FAQ

Frequently Asked Questions about Casper’s Leave Notice