Disable User Password Reset Admin Notifications Security & Risk Analysis

wordpress.org/plugins/disable-user-password-reset-emails

Disable admin email notifications when a user changes their password.

1K active installs v1.9 PHP 7.4+ WP 4.9+ Updated Apr 30, 2025
adminemailsnotifications
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Disable User Password Reset Admin Notifications Safe to Use in 2026?

Generally Safe

Score 100/100

Disable User Password Reset Admin Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The plugin 'disable-user-password-reset-emails' v1.9 exhibits a strong security posture based on the provided static analysis. It has a remarkably small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. Furthermore, the code signals indicate a commitment to secure coding practices, featuring no dangerous functions, 100% prepared statement usage for SQL queries, and proper output escaping. The absence of file operations and external HTTP requests also minimizes potential attack vectors. The plugin's vulnerability history is clean, with no known CVEs, which is a significant positive indicator. However, the complete absence of nonce and capability checks across all entry points, coupled with zero taint flows analyzed, suggests a potential gap in comprehensive security testing or a very limited scope of functionality that naturally avoids such issues. While the current data suggests a secure plugin, a lack of analysis in certain critical areas warrants a cautious approach.

Key Concerns

  • No nonce checks
  • No capability checks
  • Taint analysis not performed
Vulnerabilities
None known

Disable User Password Reset Admin Notifications Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Disable User Password Reset Admin Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Disable User Password Reset Admin Notifications Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_noticesdisable-user-password-reset-emails.php:64
actionadmin_initdisable-user-password-reset-emails.php:72
actionadmin_initdisable-user-password-reset-emails.php:115
Maintenance & Trust

Disable User Password Reset Admin Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 30, 2025
PHP min version7.4
Downloads25K

Community Trust

Rating100/100
Number of ratings5
Active installs1K
Developer Profile

Disable User Password Reset Admin Notifications Developer Profile

Chris Cook

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Disable User Password Reset Admin Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
updated
FAQ

Frequently Asked Questions about Disable User Password Reset Admin Notifications