
Email Address Obfuscation Security & Risk Analysis
wordpress.org/plugins/email-address-obfuscationEmail Address Obfuscation prevents email harvesting by hiding email address appearing in your pages, while remaining visible to your site visitors.
Is Email Address Obfuscation Safe to Use in 2026?
Generally Safe
Score 99/100Email Address Obfuscation has a strong security track record. Known vulnerabilities have been patched promptly.
The email-address-obfuscation plugin v1.2.0 exhibits a generally positive security posture based on the static analysis provided. The code adheres to good practices by not utilizing dangerous functions, employing prepared statements for all SQL queries, and properly escaping all identified output. The absence of file operations and external HTTP requests further reduces the potential attack surface. However, a significant concern arises from the lack of any explicit nonce or capability checks, particularly given the presence of a shortcode. This means that any user, regardless of their logged-in status or role, could potentially interact with the shortcode's functionality. The vulnerability history reveals one known CVE, a medium-severity Cross-site Scripting (XSS) vulnerability, which is noted as currently patched. While this specific vulnerability is addressed, the pattern of past XSS issues, even if resolved, suggests a potential for input sanitization oversight. The overall risk is moderate due to the lack of authorization checks on the shortcode entry point, creating a potential avenue for misuse, despite good coding practices in other areas.
Key Concerns
- Missing capability checks on shortcode
- Missing nonce checks on shortcode
- One past medium severity XSS vulnerability
Email Address Obfuscation Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Email Address Obfuscation <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via class Parameter
Email Address Obfuscation Code Analysis
Output Escaping
Email Address Obfuscation Attack Surface
Shortcodes 1
Maintenance & Trust
Email Address Obfuscation Maintenance & Trust
Maintenance Signals
Community Trust
Email Address Obfuscation Alternatives
Protect My Infos
protect-my-infos
Protect sensitive information like emails and phone numbers from bots with advanced obfuscation techniques.
TG Email Protection
tg-email-protection
Protect email addresses from being harvested by spammers and spambots, obfuscating them. Your visitors can still see email addresses.
Email No Bot – Prevent bots from detecting emails
email-no-bot
Humans will see the email address on your page, but robots will not.
Make Safe
makesafe
Obfuscates email addresses.
Contact Camo
planleft-contact-camo
Contact Camo protects email addresses by obfuscating or completely hiding them in both the source code and the DOM.
Email Address Obfuscation Developer Profile
1 plugin · 2K total installs
How We Detect Email Address Obfuscation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
email-address-obfuscation/style.css?ver=email-address-obfuscation/script.js?ver=HTML / DOM Fingerprints
<a href="mailto:title="">