Comment Approved Notifier Extended Security & Risk Analysis

wordpress.org/plugins/comment-approved-notifier-extended

Zero bloat, single purpose plugin that automatically sends email notifications when comments are approved. Lightweight and focused.

500 active installs v5.4 PHP 5.6+ WP 5.0+ Updated Mar 14, 2026
approveapproved-commentcommentemailnotification
99
A · Safe
CVEs total1
Unpatched0
Last CVEMar 27, 2025
Safety Verdict

Is Comment Approved Notifier Extended Safe to Use in 2026?

Generally Safe

Score 99/100

Comment Approved Notifier Extended has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 27, 2025Updated 21d ago
Risk Assessment

The "comment-approved-notifier-extended" plugin version 5.4 exhibits a generally good security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with open attack vectors, along with the use of prepared statements for SQL queries and a high percentage of properly escaped output, are strong indicators of secure coding practices. The presence of nonce and capability checks further reinforces this. Taint analysis shows no critical or high severity flows, suggesting that unsanitized user input is not being processed in a way that could lead to immediate compromise.

However, the plugin's vulnerability history is a significant concern. While there are no currently unpatched vulnerabilities, the existence of one known CVE, specifically a Cross-Site Scripting (XSS) vulnerability reported in March 2025, indicates that past security flaws have been present. The fact that this was a medium severity XSS suggests that while not critical, it could still pose a risk if not properly addressed. The pattern of past vulnerabilities, even if resolved, warrants continued vigilance and suggests a need for thorough code reviews to prevent recurrence.

In conclusion, the current version of "comment-approved-notifier-extended" appears to be relatively secure due to its minimal attack surface and good coding practices. Nevertheless, the historical presence of a medium severity XSS vulnerability necessitates a cautious approach. While the static analysis is positive, the plugin's track record suggests that ongoing monitoring and prompt patching of any future discovered vulnerabilities are crucial for maintaining a secure environment.

Key Concerns

  • One known medium severity CVE for XSS
  • Vulnerability history indicates past XSS issues
Vulnerabilities
1

Comment Approved Notifier Extended Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-30792medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Comment Approved Notifier Extended <= 5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting

Mar 27, 2025 Patched in 5.3 (7d)
Code Analysis
Analyzed Mar 16, 2026

Comment Approved Notifier Extended Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
29 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped34 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
cane_admin_page (comment-approved-notifier-extended.php:128)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Comment Approved Notifier Extended Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitcomment-approved-notifier-extended.php:28
actionadmin_enqueue_scriptscomment-approved-notifier-extended.php:109
actionadmin_menucomment-approved-notifier-extended.php:123
actioncomment_unapproved_to_approvedcomment-approved-notifier-extended.php:387
Maintenance & Trust

Comment Approved Notifier Extended Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 14, 2026
PHP min version5.6
Downloads10K

Community Trust

Rating100/100
Number of ratings7
Active installs500
Developer Profile

Comment Approved Notifier Extended Developer Profile

ufukart

3 plugins · 7K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Comment Approved Notifier Extended

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/comment-approved-notifier-extended/assets/css/admin.css/wp-content/plugins/comment-approved-notifier-extended/assets/js/admin.js

HTML / DOM Fingerprints

CSS Classes
cane-wrapcane-headercane-containercane-maincane-cardcane-card-headercane-card-bodycane-form-group
Data Attributes
id="cane-settings-form"
FAQ

Frequently Asked Questions about Comment Approved Notifier Extended