
Cryptex | E-Mail Address Protection Security & Risk Analysis
wordpress.org/plugins/cryptexCryptex transforms plain-text E-Mail-Addresses into Images - automatically - No scrapers. No harvesters. No spambots. That's our goal!
Is Cryptex | E-Mail Address Protection Safe to Use in 2026?
Generally Safe
Score 85/100Cryptex | E-Mail Address Protection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cryptex" v7.1 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, and raw SQL queries is commendable. A significant strength is the complete absence of known vulnerabilities (CVEs) in its history, suggesting a well-maintained and potentially secure codebase over time. The limited attack surface, with all entry points appearing to have authorization checks, is also a strong indicator of good security practices.
However, there are areas for concern. The most significant is the low percentage of properly escaped output (63%). This leaves a substantial portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not adequately sanitized before being displayed. Additionally, the lack of nonce checks, while not explicitly listed as unprotected entry points, can be a common oversight that leads to CSRF vulnerabilities when handling sensitive operations. The limited capability checks also warrant attention; while there are no direct indications of issues, a robust security model often relies on more granular permission enforcement.
In conclusion, "cryptex" v7.1 demonstrates several strong security foundations, particularly in its avoidance of common pitfalls like raw SQL and its clean vulnerability history. The primary weakness lies in output escaping, which requires immediate attention to mitigate XSS risks. The absence of taint analysis flows is a positive sign, but the lower percentage of output escaping could still present a risk.
Key Concerns
- Low output escaping percentage
- 0 Nonce checks present
Cryptex | E-Mail Address Protection Security Vulnerabilities
Cryptex | E-Mail Address Protection Code Analysis
Output Escaping
Cryptex | E-Mail Address Protection Attack Surface
Shortcodes 3
WordPress Hooks 28
Maintenance & Trust
Cryptex | E-Mail Address Protection Maintenance & Trust
Maintenance Signals
Community Trust
Cryptex | E-Mail Address Protection Alternatives
Change Mail Sender
cb-change-mail-sender
Easily change the default WordPress from email name and from email address.
CryptX
cryptx
No more SPAM by spiders scanning your site for email addresses!
Postie
postie
Postie allows you to create posts via email, including many advanced features not found in WordPress's default Post by Email feature.
ShopMagic – email automation
shopmagic-for-woocommerce
Flexible email automation and workflows triggered by customer and site events.
MailUp for WordPress – Email and Newsletter Subscription Form
mailup-email-and-newsletter-subscription-form
Il plugin permette di inserire sul proprio sito WordPress un form per l’iscrizione degli utenti a newsletter, campagne email e SMS.
Cryptex | E-Mail Address Protection Developer Profile
3 plugins · 11K total installs
How We Detect Cryptex | E-Mail Address Protection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cryptex/resources/css/cryptex.css/wp-content/plugins/cryptex/resources/js/cryptex.js/wp-content/plugins/cryptex/resources/fonts/cryptex.eot/wp-content/plugins/cryptex/resources/fonts/cryptex.ttf/wp-content/plugins/cryptex/resources/fonts/cryptex.woff/wp-content/plugins/cryptex/resources/fonts/cryptex.svg/wp-content/plugins/cryptex/resources/fonts/cryptex.woff2/wp-content/plugins/cryptex/resources/js/cryptex.jsver=7.1HTML / DOM Fingerprints
cryptex-wrapper<!-- Cryptex - E-Mail Address Protection --><!-- AUTO GENERATED CODE - DO NOT EDIT !!! --><!-- WP-SKELETON AUTO GENERATED FILE - DO NOT EDIT !!! --><!-- Copyright (c) 2016-2019 Andi Dittrich -->data-cryptex-iddata-cryptex-tokenCRYPtex[cryptex]