
Email Notification on Login Security & Risk Analysis
wordpress.org/plugins/email-notification-on-loginReceive an email after each successful login with the user information
Is Email Notification on Login Safe to Use in 2026?
Mostly Safe
Score 78/100Email Notification on Login is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "email-notification-on-login" plugin version 1.7.0 presents a mixed security posture. On the positive side, the static analysis shows no direct attack surface in terms of AJAX handlers, REST API routes, shortcodes, or cron events, and all SQL queries utilize prepared statements. However, a significant concern is the low percentage (25%) of properly escaped output, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. The absence of nonces on any entry points, while not explicitly a risk given the limited attack surface, is a missed security best practice that could be problematic if new entry points were added without proper security controls. The vulnerability history is a major red flag, with one known medium severity CVE for XSS that remains unpatched. This suggests a history of security weaknesses that are not being adequately addressed, posing a real risk to users.
Key Concerns
- Unpatched Medium Severity CVE
- Low percentage of properly escaped output
- Missing nonce checks on entry points
Email Notification on Login Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Email Notification on Login <= 1.6.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
Email Notification on Login Code Analysis
Output Escaping
Email Notification on Login Attack Surface
WordPress Hooks 6
Maintenance & Trust
Email Notification on Login Maintenance & Trust
Maintenance Signals
Community Trust
Email Notification on Login Alternatives
Simple Login Notification
simple-login-notification
Sends a notification email when admins and other users log in to your site.
Email notification on admin login
email-notification-on-admin-login
Sends an email to a pointed email address when an admin user logs in
Kaya Login Notification
kaya-login-notification
Sends email notification on successful login, with fully customizable settings.
KolorWeb Access Admin Notification: extreme rescue for unauthorized admin logins
kolorweb-access-admin-notification
Extreme rescue for unauthorized admin logins.
The Hack Repair Guy's Admin Login Notifier
the-hack-repair-guys-admin-login-notifier
The Hack Repair Guy's Admin Login Notifier notifies you the moment an Administrator user logs into your WordPress dashboard.
Email Notification on Login Developer Profile
28 plugins · 61K total installs
How We Detect Email Notification on Login
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.