Disable WordPress Update Notifications and auto-update Email Notifications Security & Risk Analysis

wordpress.org/plugins/disable-update-notifications

Disables WordPress core update notification and plugins update notification update checks and notifications.

10K active installs v2.4.2 PHP + WP 5.0+ Updated Jun 10, 2025
core-updatedisablehide-warningsplugin-updateupdate-notifications
100
A · Safe
CVEs total1
Unpatched0
Last CVEMay 30, 2023
Safety Verdict

Is Disable WordPress Update Notifications and auto-update Email Notifications Safe to Use in 2026?

Generally Safe

Score 100/100

Disable WordPress Update Notifications and auto-update Email Notifications has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 30, 2023Updated 9mo ago
Risk Assessment

The "disable-update-notifications" plugin v2.4.2 exhibits a strong security posture based on static analysis. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, or external HTTP requests is commendable. Crucially, there are no identified flows with unsanitized paths, and the total entry points are zero, meaning there are no direct ways for an attacker to interact with the plugin's code. The presence of nonce and capability checks on its limited code signals further strengthens its defense.

However, a single medium-severity vulnerability in the past, specifically a Cross-Site Request Forgery (CSRF), warrants attention. While there are no currently unpatched vulnerabilities, this history suggests that while the plugin has addressed past issues, the potential for similar vulnerabilities may still exist if development practices deviate. The plugin's strengths lie in its minimal attack surface and adherence to secure coding practices in its current analysis. Its weakness is the historical presence of a CSRF vulnerability, which, although patched, indicates a past area of concern.

Overall, the plugin demonstrates good security hygiene. The static analysis shows an excellent effort to avoid common vulnerabilities. The historical vulnerability, while concerning, was patched and is not currently an active threat. The plugin is generally safe to use, but users should remain vigilant about future updates and monitor for any newly disclosed vulnerabilities, especially those related to CSRF.

Key Concerns

  • Past medium vulnerability (CSRF)
Vulnerabilities
1

Disable WordPress Update Notifications and auto-update Email Notifications Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-34029medium · 4.3Cross-Site Request Forgery (CSRF)

Disable WordPress Update Notifications <= 2.3.3 - Cross-Site Request Forgery

May 30, 2023 Patched in 2.4.0 (238d)
Code Analysis
Analyzed Mar 16, 2026

Disable WordPress Update Notifications and auto-update Email Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
dwun_plugin_settings (css\index.php:27)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Disable WordPress Update Notifications and auto-update Email Notifications Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionadmin_enqueue_scriptscss\index.php:25
actionadmin_menucss\index.php:185
filterpre_site_transient_update_pluginscss\index.php:193
filterpre_site_transient_update_themescss\index.php:199
actionafter_setup_themecss\index.php:204
filterpre_option_update_corecss\index.php:209
filterpre_site_transient_update_corecss\index.php:210
filterauto_plugin_update_send_emailcss\index.php:221
filterauto_theme_update_send_emailcss\index.php:223
actionadmin_enqueue_scriptsindex.php:27
actionadmin_menuindex.php:187
filterpre_site_transient_update_pluginsindex.php:195
filterpre_site_transient_update_themesindex.php:201
actionafter_setup_themeindex.php:206
filterpre_option_update_coreindex.php:211
filterpre_site_transient_update_coreindex.php:212
filterauto_plugin_update_send_emailindex.php:223
filterauto_theme_update_send_emailindex.php:225
Maintenance & Trust

Disable WordPress Update Notifications and auto-update Email Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 10, 2025
PHP min version
Downloads77K

Community Trust

Rating88/100
Number of ratings18
Active installs10K
Developer Profile

Disable WordPress Update Notifications and auto-update Email Notifications Developer Profile

Prem Tiwari

10 plugins · 12K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
238 days
View full developer profile
Detection Fingerprints

How We Detect Disable WordPress Update Notifications and auto-update Email Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/disable-update-notifications/css/admin-style.css

HTML / DOM Fingerprints

CSS Classes
onoffswitchonoffswitch-checkboxonoffswitch-labelonoffswitch-inneronoffswitch-switchwbcr-factory-page-headertabordionwbcr-factory-tab__short-description+4 more
Data Attributes
for="dpun"for="dwtu"for="dwcun"for="den"name="dpun"name="dwtu"+12 more
FAQ

Frequently Asked Questions about Disable WordPress Update Notifications and auto-update Email Notifications