Disable Lost Password Email Security & Risk Analysis

wordpress.org/plugins/disable-lost-password-email

Use this plugin to Disable Lost Password Email functionality.

40 active installs v2.2.0 PHP + WP 5.0+ Updated Jan 5, 2021
disable-emaildisable-lost-passwordlost-password-emailwordpress-disable-lost-passwordwordpress-disable-lost-password-email
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Disable Lost Password Email Safe to Use in 2026?

Generally Safe

Score 85/100

Disable Lost Password Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "disable-lost-password-email" v2.2.0 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals a complete absence of dangerous functions, SQL queries without prepared statements, unescaped output, file operations, external HTTP requests, and vulnerability-free taint analysis. Notably, there are zero entry points, and consequently, zero unprotected entry points. This indicates a highly secure development approach where all potential interaction points are either absent or well-protected.

The vulnerability history further reinforces this positive assessment, showing no known CVEs of any severity. This lack of historical vulnerabilities suggests either consistent good security practices over time or that the plugin's functionality is so limited that it presents no attractive targets for exploitation. The absence of bundled libraries also removes a common vector for introducing vulnerabilities through outdated dependencies.

In conclusion, this plugin appears to be exceptionally secure. Its minimal attack surface and clean code, combined with a spotless vulnerability record, make it a low-risk choice. The only potential, albeit theoretical, concern would be the lack of explicit capability checks and nonce checks. However, given the complete absence of entry points, these checks are not presently required and thus don't represent a current security flaw.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Disable Lost Password Email Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Disable Lost Password Email Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Disable Lost Password Email Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
filterallow_password_resetclasses\class.disable.email.php:14
Maintenance & Trust

Disable Lost Password Email Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedJan 5, 2021
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Disable Lost Password Email Developer Profile

Yogesh Pawar

11 plugins · 600 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disable Lost Password Email

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/disable-lost-password-email/classes/class.disable.email.php
Version Parameters
disable-lost-password-email?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Disable Lost Password Email