
Casper’s Leave Notice Security & Risk Analysis
wordpress.org/plugins/caspers-leave-noticeA quick, easy way to notify your users when they are leaving your site. You can edit the content and add domain exclusions.
Is Casper’s Leave Notice Safe to Use in 2026?
Generally Safe
Score 85/100Casper’s Leave Notice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The caspers-leave-notice plugin v1.2.3 exhibits a generally strong security posture in several key areas. The absence of known vulnerabilities (CVEs) and the lack of any critical or high-severity taint flows are positive indicators. Furthermore, the plugin's entry points (AJAX handlers, REST API routes, shortcodes, cron events) are all reported as protected, which is excellent. The plugin also avoids potentially risky operations like file operations and external HTTP requests.
However, a significant concern arises from the output escaping. With 9 total outputs and 0% properly escaped, this presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities. Any data displayed to users that originates from or is processed by the plugin without proper sanitization could be manipulated to inject malicious scripts. The complete lack of capability checks, while not directly a vulnerability in itself, means that access controls are not being enforced at the plugin level, relying entirely on WordPress's core roles and permissions. This could be problematic if certain functionalities are intended for specific user roles only.
In conclusion, while the plugin's attack surface is well-managed and it has a clean vulnerability history, the pervasive issue with output escaping is a critical weakness that requires immediate attention. This oversight could easily lead to exploitable XSS flaws. Addressing the output escaping is paramount to improving the plugin's security.
Key Concerns
- 0% output escaping
- 0 capability checks
Casper’s Leave Notice Security Vulnerabilities
Casper’s Leave Notice Release Timeline
Casper’s Leave Notice Code Analysis
Output Escaping
Casper’s Leave Notice Attack Surface
WordPress Hooks 9
Maintenance & Trust
Casper’s Leave Notice Maintenance & Trust
Maintenance Signals
Community Trust
Casper’s Leave Notice Alternatives
External Links – nofollow, noopener & new window
wp-external-links
Internal links & external links manager: open in new window or tab, control nofollow, ugc, sponsored & noopener. SEO friendly.
External Links in New Window / New Tab
open-external-links-in-a-new-window
Open external links in a new window or new tab. SEO optimized and XHTML Strict compliant.
External Links
sem-external-links
The external links plugin for WordPress lets you process outgoing links differently from internal links.
Open Links In New Tab
open-links-in-new-tab
Opens external links and internal links in a new window depending on user settings. Manage all external & internal links on your site.
External Links Overview
external-links-overview
Analyze, manage, and monitor all external links on your WordPress site. ---
Casper’s Leave Notice Developer Profile
2 plugins · 400 total installs
How We Detect Casper’s Leave Notice
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/caspers-leave-notice/caspers-leave-notice.css/wp-content/plugins/caspers-leave-notice/caspers-leave-notice.jscaspers-leave-notice/caspers-leave-notice.css?ver=caspers-leave-notice/caspers-leave-notice.js?ver=HTML / DOM Fingerprints
cpln-leavenoticecpln-positioncpln-overlaycpln-tbcpln-tdcpln-contentcpln-redirect-boxcpln-redirect-box__content+6 moredata-start-time