Email id from comments Security & Risk Analysis

wordpress.org/plugins/email-id-from-comments

This plugin extracts the email ids from the comments in your website. It can get email id from any comment which you have not deleted (approved,spam).

0 active installs v1.2 PHP + WP 4.5+ Updated Apr 27, 2017
commentsemailget-email-id-from-comments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Email id from comments Safe to Use in 2026?

Generally Safe

Score 85/100

Email id from comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "email-id-from-comments" plugin v1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface, and there are no identified entry points that lack authentication checks. Furthermore, the code signals indicate no dangerous functions are in use and the single SQL query utilizes prepared statements, which is a positive practice.

However, a critical concern arises from the output escaping analysis. With 100% of outputs not being properly escaped (3 total outputs), there is a clear risk of cross-site scripting (XSS) vulnerabilities. This means that any data processed by the plugin that is later displayed to users, even if not directly user-controlled through an obvious entry point, could potentially be exploited.

The vulnerability history further reinforces the lack of previously identified security issues, suggesting a developer who may be security-conscious. Despite this, the identified lack of output escaping presents a tangible risk that needs immediate attention to ensure the plugin's overall security.

Key Concerns

  • Unescaped output found
Vulnerabilities
None known

Email id from comments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Email id from comments Release Timeline

v1.2Current
Code Analysis
Analyzed Apr 16, 2026

Email id from comments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
3
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

0% escaped3 total outputs
Attack Surface

Email id from comments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_menuemail-id-from-comments.php:12
Maintenance & Trust

Email id from comments Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedApr 27, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Email id from comments Developer Profile

Bishoy.A

13 plugins · 11K total installs

82
trust score
Avg Security Score
92/100
Avg Patch Time
89 days
View full developer profile
Detection Fingerprints

How We Detect Email id from comments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/email-id-from-comments/eifc_25042017_main.css

HTML / DOM Fingerprints

CSS Classes
containeremail-holder
FAQ

Frequently Asked Questions about Email id from comments