
Comment Approved Notifier Extended Security & Risk Analysis
wordpress.org/plugins/comment-approved-notifier-extendedZero bloat, single purpose plugin that automatically sends email notifications when comments are approved. Lightweight and focused.
Is Comment Approved Notifier Extended Safe to Use in 2026?
Generally Safe
Score 99/100Comment Approved Notifier Extended has a strong security track record. Known vulnerabilities have been patched promptly.
The "comment-approved-notifier-extended" plugin version 5.4 exhibits a generally good security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with open attack vectors, along with the use of prepared statements for SQL queries and a high percentage of properly escaped output, are strong indicators of secure coding practices. The presence of nonce and capability checks further reinforces this. Taint analysis shows no critical or high severity flows, suggesting that unsanitized user input is not being processed in a way that could lead to immediate compromise.
However, the plugin's vulnerability history is a significant concern. While there are no currently unpatched vulnerabilities, the existence of one known CVE, specifically a Cross-Site Scripting (XSS) vulnerability reported in March 2025, indicates that past security flaws have been present. The fact that this was a medium severity XSS suggests that while not critical, it could still pose a risk if not properly addressed. The pattern of past vulnerabilities, even if resolved, warrants continued vigilance and suggests a need for thorough code reviews to prevent recurrence.
In conclusion, the current version of "comment-approved-notifier-extended" appears to be relatively secure due to its minimal attack surface and good coding practices. Nevertheless, the historical presence of a medium severity XSS vulnerability necessitates a cautious approach. While the static analysis is positive, the plugin's track record suggests that ongoing monitoring and prompt patching of any future discovered vulnerabilities are crucial for maintaining a secure environment.
Key Concerns
- One known medium severity CVE for XSS
- Vulnerability history indicates past XSS issues
Comment Approved Notifier Extended Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Comment Approved Notifier Extended <= 5.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Comment Approved Notifier Extended Code Analysis
Output Escaping
Data Flow Analysis
Comment Approved Notifier Extended Attack Surface
WordPress Hooks 4
Maintenance & Trust
Comment Approved Notifier Extended Maintenance & Trust
Maintenance Signals
Community Trust
Comment Approved Notifier Extended Alternatives
Comment Reply Email Notification
comment-reply-email-notification
This plugin allows visitors to subscribe to get answers to their comments via e-mail.
Comment Email Reply
comment-email-reply
Simply notifies comment-author via email if someone replies to his comment. Zero Configuration.
Comment Approved
comment-approved
Notify a user when their comment is approved.
Comment Reply Email
comment-reply-email
Commenters can receive email notifications of replies to their comments.
WP Comment Notification
wp-comment-notification
Send email notification to predefined email ids when someone comments on your blog.
Comment Approved Notifier Extended Developer Profile
3 plugins · 7K total installs
How We Detect Comment Approved Notifier Extended
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/comment-approved-notifier-extended/assets/css/admin.css/wp-content/plugins/comment-approved-notifier-extended/assets/js/admin.jsHTML / DOM Fingerprints
cane-wrapcane-headercane-containercane-maincane-cardcane-card-headercane-card-bodycane-form-groupid="cane-settings-form"