
Email id from comments Security & Risk Analysis
wordpress.org/plugins/email-id-from-commentsThis plugin extracts the email ids from the comments in your website. It can get email id from any comment which you have not deleted (approved,spam).
Is Email id from comments Safe to Use in 2026?
Generally Safe
Score 85/100Email id from comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "email-id-from-comments" plugin v1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface, and there are no identified entry points that lack authentication checks. Furthermore, the code signals indicate no dangerous functions are in use and the single SQL query utilizes prepared statements, which is a positive practice.
However, a critical concern arises from the output escaping analysis. With 100% of outputs not being properly escaped (3 total outputs), there is a clear risk of cross-site scripting (XSS) vulnerabilities. This means that any data processed by the plugin that is later displayed to users, even if not directly user-controlled through an obvious entry point, could potentially be exploited.
The vulnerability history further reinforces the lack of previously identified security issues, suggesting a developer who may be security-conscious. Despite this, the identified lack of output escaping presents a tangible risk that needs immediate attention to ensure the plugin's overall security.
Key Concerns
- Unescaped output found
Email id from comments Security Vulnerabilities
Email id from comments Release Timeline
Email id from comments Code Analysis
SQL Query Safety
Output Escaping
Email id from comments Attack Surface
WordPress Hooks 1
Maintenance & Trust
Email id from comments Maintenance & Trust
Maintenance Signals
Community Trust
Email id from comments Alternatives
Disqus Comment System
disqus-comment-system
Disqus is the web's most popular comment system. Use Disqus to increase engagement, retain readers, and grow your audience.
Subscribe to Comments
subscribe-to-comments
Subscribe to Comments allows commenters on an entry to subscribe to e-mail notifications for subsequent comments.
Subscribe To Comments Reloaded
subscribe-to-comments-reloaded
Subscribe to Comments Reloaded allows commenters to sign up for e-mail notifications of subsequent replies. Don't miss any comment.
Comment Email Reply
comment-email-reply
Simply notifies comment-author via email if someone replies to his comment. Zero Configuration.
Comment Notifier
comment-notifier
Add comment subscriptions to the blog comment form.
Email id from comments Developer Profile
13 plugins · 11K total installs
How We Detect Email id from comments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/email-id-from-comments/eifc_25042017_main.cssHTML / DOM Fingerprints
containeremail-holder