En Spam Security & Risk Analysis

wordpress.org/plugins/en-spam

Block spam with cookies and JavaScript. All Spambots will remain away from your blog. Without settings or Captcha, install and forget the spam.

600 active installs v1.1 PHP + WP 2.0+ Updated Nov 30, 2025
anti-spamblock-spambotcommentspam
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is En Spam Safe to Use in 2026?

Generally Safe

Score 100/100

En Spam has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The en-spam plugin v1.1 exhibits a strong security posture based on the provided static analysis. There are no identified entry points in the attack surface, no dangerous functions utilized, and all SQL queries are properly prepared. This suggests a well-written plugin with a minimal attack surface. The lack of vulnerability history further reinforces this positive assessment, indicating a history of secure development and maintenance. However, a single instance of unescaped output, while not a critical finding in isolation given the absence of other vulnerabilities, does represent a potential weakness that could be exploited in a more complex scenario or if combined with other vulnerabilities. While the plugin's current state is highly secure, diligent attention to output escaping remains a best practice.

Key Concerns

  • Unescaped output found
Vulnerabilities
None known

En Spam Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

En Spam Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

En Spam Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterpreprocess_commenten-spam.php:18
actionwp_enqueue_scriptsen-spam.php:19
actionwp_dashboard_setupen-spam.php:20
actionwpcf7_before_send_mailen-spam.php:21
actionelementor_pro/forms/validationen-spam.php:22
Maintenance & Trust

En Spam Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 30, 2025
PHP min version
Downloads17K

Community Trust

Rating82/100
Number of ratings7
Active installs600
Developer Profile

En Spam Developer Profile

hatul

4 plugins · 1K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect En Spam

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/en-spam/
Script Paths
/wp-content/plugins/en-spam/en-spam.js

HTML / DOM Fingerprints

JS Globals
en_spam_validate
Shortcode Output
<input type="hidden" name="code" value="
FAQ

Frequently Asked Questions about En Spam