Conversation Notifier for ElevenLabs Agents Security & Risk Analysis

wordpress.org/plugins/conversation-notifier-for-elevenlabs-agents

Receive email alerts when an ElevenLabs Agent conversation ends. Secure via URL token or HMAC, with logs, rate limiting, and tidy summaries.

0 active installs v0.7.6 PHP 7.4+ WP 6.2+ Updated Sep 8, 2025
aielevenlabsemailnotifierwebhook
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Conversation Notifier for ElevenLabs Agents Safe to Use in 2026?

Generally Safe

Score 100/100

Conversation Notifier for ElevenLabs Agents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "conversation-notifier-for-elevenlabs-agents" plugin, version 0.7.6, exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with exposed entry points significantly limits its attack surface. Furthermore, the code signals indicate good practices such as 100% usage of prepared statements for SQL queries and a sufficient number of nonce and capability checks. The lack of dangerous functions and taint flows also suggests a low risk of common injection vulnerabilities.

However, a significant concern lies in the output escaping. With 64% of outputs properly escaped, a notable 36% remain unescaped. This leaves room for potential cross-site scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed on the frontend or admin area. The presence of two external HTTP requests, while not inherently risky, warrants attention to ensure they are made securely and do not expose sensitive information or introduce supply chain risks. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive indicator of its current security status, but it doesn't negate the risks identified in the static analysis.

In conclusion, the plugin benefits from a minimal attack surface and robust handling of database interactions and authorization. The primary area of concern is the unescaped output, which requires immediate attention. While the absence of historical vulnerabilities is reassuring, the static analysis highlights a specific weakness that could be exploited. Addressing the unescaped output is crucial to maintaining a secure plugin.

Key Concerns

  • Unescaped output detected
  • External HTTP requests present
Vulnerabilities
None known

Conversation Notifier for ElevenLabs Agents Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Conversation Notifier for ElevenLabs Agents Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
54
98 escaped
Nonce Checks
12
Capability Checks
8
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

64% escaped152 total outputs
Attack Surface

Conversation Notifier for ElevenLabs Agents Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 22
actionadmin_menuconversation-notifier-for-elevenlabs-agents.php:31
actionadmin_initconversation-notifier-for-elevenlabs-agents.php:32
actionrest_api_initconversation-notifier-for-elevenlabs-agents.php:33
actionplugins_loadedconversation-notifier-for-elevenlabs-agents.php:34
actionadmin_post_elcn_send_test_emailconversation-notifier-for-elevenlabs-agents.php:35
actionadmin_post_elcn_rotate_tokenconversation-notifier-for-elevenlabs-agents.php:36
actionadmin_post_elcn_self_testconversation-notifier-for-elevenlabs-agents.php:37
actionupdated_optionconversation-notifier-for-elevenlabs-agents.php:38
filterwp_mail_fromconversation-notifier-for-elevenlabs-agents.php:665
filterwp_mail_from_nameconversation-notifier-for-elevenlabs-agents.php:673
filtersite_status_testsconversation-notifier-for-elevenlabs-agents.php:681
actionadmin_menutrunk\conversation-notifier-for-elevenlabs-agents.php:31
actionadmin_inittrunk\conversation-notifier-for-elevenlabs-agents.php:32
actionrest_api_inittrunk\conversation-notifier-for-elevenlabs-agents.php:33
actionplugins_loadedtrunk\conversation-notifier-for-elevenlabs-agents.php:34
actionadmin_post_elcn_send_test_emailtrunk\conversation-notifier-for-elevenlabs-agents.php:35
actionadmin_post_elcn_rotate_tokentrunk\conversation-notifier-for-elevenlabs-agents.php:36
actionadmin_post_elcn_self_testtrunk\conversation-notifier-for-elevenlabs-agents.php:37
actionupdated_optiontrunk\conversation-notifier-for-elevenlabs-agents.php:38
filterwp_mail_fromtrunk\conversation-notifier-for-elevenlabs-agents.php:665
filterwp_mail_from_nametrunk\conversation-notifier-for-elevenlabs-agents.php:673
filtersite_status_teststrunk\conversation-notifier-for-elevenlabs-agents.php:681
Maintenance & Trust

Conversation Notifier for ElevenLabs Agents Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 8, 2025
PHP min version7.4
Downloads330

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Conversation Notifier for ElevenLabs Agents Developer Profile

Fahad Aslam

2 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Conversation Notifier for ElevenLabs Agents

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
/wp-json/conversation-notifier-for-elevenlabs-agents/v1/post-call
FAQ

Frequently Asked Questions about Conversation Notifier for ElevenLabs Agents