
Email Notification On Comment Approval Security & Risk Analysis
wordpress.org/plugins/email-notification-on-comment-approvalThis plugin notifies the comment auther by email on approval of his/her Comment.
Is Email Notification On Comment Approval Safe to Use in 2026?
Generally Safe
Score 85/100Email Notification On Comment Approval has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "email-notification-on-comment-approval" plugin v0.1 shows a mixed bag of good practices and significant concerns. On the positive side, there are no registered CVEs, no external HTTP requests, and all SQL queries utilize prepared statements, which are excellent indicators of security awareness. The absence of a broad attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events is also a strength. However, the code analysis reveals critical weaknesses. The presence of the `create_function` is a major concern as it's deprecated and can lead to serious security vulnerabilities if not handled with extreme care, potentially allowing for code injection. Furthermore, a staggering 100% of the outputs are not properly escaped, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis indicating unsanitized paths, even without critical or high severity flags, warrants attention as it suggests potential for unintended data handling.
While the plugin boasts a clean vulnerability history, this could be due to its limited complexity or lack of extensive review. The current findings, particularly the unescaped outputs and the use of `create_function`, represent immediate and significant risks. The lack of capability checks and nonce checks, combined with the unescaped outputs, makes the plugin highly susceptible to XSS attacks, especially if any of its entry points were ever to become exposed. The overall conclusion is that while the plugin avoids common pitfalls like unpatched CVEs and raw SQL, its internal code quality regarding output sanitization and the use of dangerous functions poses substantial risks that need to be addressed.
Key Concerns
- Unescaped output (100%)
- Dangerous function: create_function
- Taint analysis: unsanitized paths
- No capability checks
- No nonce checks
Email Notification On Comment Approval Security Vulnerabilities
Email Notification On Comment Approval Release Timeline
Email Notification On Comment Approval Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Email Notification On Comment Approval Attack Surface
WordPress Hooks 5
Maintenance & Trust
Email Notification On Comment Approval Maintenance & Trust
Maintenance Signals
Community Trust
Email Notification On Comment Approval Alternatives
Comment Email Reply
comment-email-reply
Simply notifies comment-author via email if someone replies to his comment. Zero Configuration.
WP Comment Notification
wp-comment-notification
Send email notification to predefined email ids when someone comments on your blog.
Subscribe To Comments Checkbox
comments-subscribe-checkbox
This plugin will allow you to add subscribe notification checkbox to comments on your site.
No Comment
no-comment
No Comment is a simple way to remove email notification for just one person out of your list of blog administrators.
Simple Comment Notification
simple-comment-notification
Sends an simply email notification to the comment author, when someone replies to his comment.
Email Notification On Comment Approval Developer Profile
1 plugin · 10 total installs
How We Detect Email Notification On Comment Approval
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
notificationid="enocp_from"name="enocp_from"id="enocp_cc"name="enocp_cc"id="enocp_bcc"name="enocp_bcc"+7 more