
Disable Admin Email Security & Risk Analysis
wordpress.org/plugins/disable-admin-emailTurns off the notification sent to the admin email when a new user account is registered.
Is Disable Admin Email Safe to Use in 2026?
Generally Safe
Score 92/100Disable Admin Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "disable-admin-email" plugin v1.0.0 exhibits an exceptionally clean static analysis profile, indicating a strong adherence to secure coding practices. The absence of any dangerous functions, SQL queries not using prepared statements, unescaped output, file operations, external HTTP requests, or identified taint flows is highly commendable. Furthermore, the plugin's vulnerability history is completely clear, with no recorded CVEs of any severity. This suggests a well-developed and thoroughly reviewed piece of code.
However, the complete lack of any capability checks or nonce checks is a significant concern. While the plugin's current attack surface is reported as zero, this could be due to its specific functionality not requiring direct user interaction via standard WordPress mechanisms. If future functionality is added or if the plugin's role changes, the absence of these fundamental security checks could expose it to vulnerabilities. The zero entry points without authentication is a positive sign, but the underlying lack of authorization checks on potential future entry points is a weakness.
Key Concerns
- Missing capability checks
- Missing nonce checks
Disable Admin Email Security Vulnerabilities
Disable Admin Email Release Timeline
Disable Admin Email Code Analysis
Disable Admin Email Attack Surface
WordPress Hooks 2
Maintenance & Trust
Disable Admin Email Maintenance & Trust
Maintenance Signals
Community Trust
Disable Admin Email Developer Profile
1 plugin · 10 total installs
How We Detect Disable Admin Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.