
Change Admin Email Security & Risk Analysis
wordpress.org/plugins/change-admin-email-setting-without-outbound-emailThis plugin allows an administrator to change the "site admin email", without sending a confirmation email from the server.
Is Change Admin Email Safe to Use in 2026?
Generally Safe
Score 92/100Change Admin Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'change-admin-email-setting-without-outbound-email' version 4.1 exhibits a strong security posture based on the provided static analysis. The absence of any entry points like AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code analysis shows no dangerous functions, all SQL queries are properly prepared, and there are no taint flows with unsanitized paths, indicating good secure coding practices. The presence of nonce and capability checks, along with proper output escaping for the vast majority of outputs, further reinforces this positive assessment. The single external HTTP request is a potential area for monitoring, but without further context, its risk is minimal.
The vulnerability history is remarkably clean, with zero recorded CVEs of any severity. This pattern suggests a well-maintained and secure plugin, or potentially a plugin that has not been a significant target or focus for vulnerability research. However, it's important to note that a lack of history doesn't guarantee future security. The plugin's strengths lie in its minimal attack surface and adherence to secure coding principles for its detected code. Its primary weakness, if any, would be the potential for unknown vulnerabilities due to its limited historical record, although the static analysis provides a high degree of confidence in its current safety.
Change Admin Email Security Vulnerabilities
Change Admin Email Code Analysis
Output Escaping
Change Admin Email Attack Surface
WordPress Hooks 9
Maintenance & Trust
Change Admin Email Maintenance & Trust
Maintenance Signals
Community Trust
Change Admin Email Alternatives
Multiple Admin Email Addresses
multiple-admin-email-addresses
Multiple Admin Email Addresses allows you to replace the blog's admin email with a comma separated list of admin emails
Disable User Registration Notification Emails
disable-user-registration-notification-emails
Turns off the notification sent to the admin email when a new user account is registered. Works with WP >= 4.6.0.
Send Email From Admin
send-email-from-admin
Easily send a simple custom email with an attachment from the WordPress administration screen.
Disable New User Notification
disable-wp-new-user-notification
This plugin disables the email sent to the site admin each time a new user creates an account.
The Hack Repair Guy's Admin Login Notifier
the-hack-repair-guys-admin-login-notifier
The Hack Repair Guy's Admin Login Notifier notifies you the moment an Administrator user logs into your WordPress dashboard.
Change Admin Email Developer Profile
2 plugins · 50K total installs
How We Detect Change Admin Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/change-admin-email-setting-without-outbound-email/change-admin-email.js/wp-content/plugins/change-admin-email-setting-without-outbound-email/change-admin-email.jschange-admin-email-setting-without-outbound-email/change-admin-email.js?ver=1.0HTML / DOM Fingerprints
noticenotice-errornotice-warningnotice-infonotice-successis-dismissibledata-noncechange_admin_email_data/wp-json/change-admin-email-plugin/v1/test-email