Cryptex | E-Mail Address Protection Security & Risk Analysis

wordpress.org/plugins/cryptex

Cryptex transforms plain-text E-Mail-Addresses into Images - automatically - No scrapers. No harvesters. No spambots. That's our goal!

900 active installs v7.1 PHP + WP 3.9+ Updated Apr 1, 2020
e-mailemailgrabbingprivacyrobots
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cryptex | E-Mail Address Protection Safe to Use in 2026?

Generally Safe

Score 85/100

Cryptex | E-Mail Address Protection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "cryptex" v7.1 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, and raw SQL queries is commendable. A significant strength is the complete absence of known vulnerabilities (CVEs) in its history, suggesting a well-maintained and potentially secure codebase over time. The limited attack surface, with all entry points appearing to have authorization checks, is also a strong indicator of good security practices.

However, there are areas for concern. The most significant is the low percentage of properly escaped output (63%). This leaves a substantial portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks if user-supplied data is not adequately sanitized before being displayed. Additionally, the lack of nonce checks, while not explicitly listed as unprotected entry points, can be a common oversight that leads to CSRF vulnerabilities when handling sensitive operations. The limited capability checks also warrant attention; while there are no direct indications of issues, a robust security model often relies on more granular permission enforcement.

In conclusion, "cryptex" v7.1 demonstrates several strong security foundations, particularly in its avoidance of common pitfalls like raw SQL and its clean vulnerability history. The primary weakness lies in output escaping, which requires immediate attention to mitigate XSS risks. The absence of taint analysis flows is a positive sign, but the lower percentage of output escaping could still present a risk.

Key Concerns

  • Low output escaping percentage
  • 0 Nonce checks present
Vulnerabilities
None known

Cryptex | E-Mail Address Protection Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Cryptex | E-Mail Address Protection Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
40 escaped
Nonce Checks
0
Capability Checks
1
File Operations
11
External Requests
0
Bundled Libraries
0

Output Escaping

63% escaped64 total outputs
Attack Surface

Cryptex | E-Mail Address Protection Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[cryptex] modules\cryptex\ShortcodeHandler.php:18
[email] modules\cryptex\ShortcodeHandler.php:24
[telephone] modules\cryptex\ShortcodeHandler.php:30
WordPress Hooks 28
actionadmin_noticesCryptex.php:72
actionnetwork_admin_noticesCryptex.php:73
filterthe_contentmodules\cryptex\AutodetectFilter.php:33
filterget_the_excerptmodules\cryptex\AutodetectFilter.php:38
filterget_comment_textmodules\cryptex\AutodetectFilter.php:43
filterget_comment_excerptmodules\cryptex\AutodetectFilter.php:48
filterwidget_textmodules\cryptex\AutodetectFilter.php:53
actionupgrader_post_installmodules\cryptex\Cryptex.php:60
actionshutdownmodules\cryptex\Cryptex.php:63
actionwp_footermodules\cryptex\HdpiCssRenderer.php:19
actionadmin_enqueue_scriptsmodules\cryptex\ResourceLoader.php:47
filterno_texturize_shortcodesmodules\cryptex\ShortcodeHandler.php:34
actionupgrader_pre_installmodules\cryptex\Updater.php:17
actionupgrader_post_installmodules\cryptex\Updater.php:18
actionadmin_menumodules\skltn\Plugin.php:59
actionin_plugin_update_message-cryptex/Cryptex.phpmodules\skltn\Plugin.php:62
actionadmin_noticesmodules\skltn\Plugin.php:67
actionnetwork_admin_noticesmodules\skltn\Plugin.php:68
actionadmin_initmodules\skltn\Plugin.php:84
filterplugin_action_linksmodules\skltn\Plugin.php:87
filterplugin_row_metamodules\skltn\Plugin.php:88
actioninitmodules\skltn\Plugin.php:272
actioninitmodules\skltn\Plugin.php:273
actionwp_footermodules\skltn\ResourceManager.php:85
actionwp_headmodules\skltn\ResourceManager.php:102
filterrewrite_rules_arraymodules\skltn\RewriteRuleHelper.php:78
actiontemplate_redirectmodules\skltn\VirtualPageManager.php:32
actioncryptex_rewriterules_initmodules\skltn\VirtualPageManager.php:35
Maintenance & Trust

Cryptex | E-Mail Address Protection Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 1, 2020
PHP min version
Downloads20K

Community Trust

Rating80/100
Number of ratings4
Active installs900
Developer Profile

Cryptex | E-Mail Address Protection Developer Profile

Andi Dittrich

3 plugins · 11K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cryptex | E-Mail Address Protection

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cryptex/resources/css/cryptex.css/wp-content/plugins/cryptex/resources/js/cryptex.js/wp-content/plugins/cryptex/resources/fonts/cryptex.eot/wp-content/plugins/cryptex/resources/fonts/cryptex.ttf/wp-content/plugins/cryptex/resources/fonts/cryptex.woff/wp-content/plugins/cryptex/resources/fonts/cryptex.svg/wp-content/plugins/cryptex/resources/fonts/cryptex.woff2
Script Paths
/wp-content/plugins/cryptex/resources/js/cryptex.js
Version Parameters
ver=7.1

HTML / DOM Fingerprints

CSS Classes
cryptex-wrapper
HTML Comments
<!-- Cryptex - E-Mail Address Protection --><!-- AUTO GENERATED CODE - DO NOT EDIT !!! --><!-- WP-SKELETON AUTO GENERATED FILE - DO NOT EDIT !!! --><!-- Copyright (c) 2016-2019 Andi Dittrich -->
Data Attributes
data-cryptex-iddata-cryptex-token
JS Globals
CRYPtex
Shortcode Output
[cryptex]
FAQ

Frequently Asked Questions about Cryptex | E-Mail Address Protection