
Full Detail From Email Security & Risk Analysis
wordpress.org/plugins/full-detail-from-emailUsing the Full Detail From Email with just an emai address you get all required and available information about subscriber.
Is Full Detail From Email Safe to Use in 2026?
Generally Safe
Score 85/100Full Detail From Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'full-detail-from-email' v2.2.5 plugin exhibits significant security concerns, primarily stemming from its unprotected entry points and insecure handling of user-supplied data. With two AJAX handlers lacking authentication checks and a critical taint flow involving unsanitized paths, the plugin presents a substantial risk for attackers to potentially inject malicious code or manipulate data. The presence of the 'unserialize' function, especially without clear input validation or sanitization mechanisms, is a known vector for serious vulnerabilities. While the plugin has no recorded CVEs, this does not guarantee its current safety, as the static analysis reveals fundamental security weaknesses that could lead to undiscovered vulnerabilities.
The plugin's vulnerability history is currently clean, which is a positive sign. However, this lack of recorded history should not overshadow the critical findings in the static analysis. The substantial number of flows with unsanitized paths, particularly four designated as high severity, strongly indicates potential for exploitation. The limited use of prepared statements for SQL queries and the low percentage of properly escaped output further amplify these concerns, suggesting that data injected through the unprotected entry points could be used to compromise the database or lead to cross-site scripting (XSS) vulnerabilities. The absence of nonce and capability checks on its AJAX endpoints is a direct invitation for unauthorized actions.
In conclusion, while the absence of known vulnerabilities is a positive aspect, the 'full-detail-from-email' v2.2.5 plugin has a poor security posture due to critical vulnerabilities identified in the static analysis. The unprotected AJAX handlers, high-severity unsanitized taint flows, use of 'unserialize' without apparent sanitization, and weak SQL and output escaping practices create significant risks. It is strongly recommended that this plugin be audited and updated by its developers to address these critical security flaws before it can be considered safe for use.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Dangerous function: unserialize
- Low percentage of prepared SQL statements
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Full Detail From Email Security Vulnerabilities
Full Detail From Email Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Full Detail From Email Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Full Detail From Email Maintenance & Trust
Maintenance Signals
Community Trust
Full Detail From Email Alternatives
User IP and Location
user-ip-and-location
Want to show your website visitors their IP address, location, and other cool details? This plugin makes it super easy! Now works perfectly with cachi …
User Allowed IP Addresses
user-allowed-ip-addresses
Simple plugin that gives the ability to restrict login access to specific IP addresses for specific users. Option to Auto Login user based on IP.
Full Detail From Email Developer Profile
1 plugin · 0 total installs
How We Detect Full Detail From Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/full-detail-from-email/admin/assets/css/style.css/wp-content/plugins/full-detail-from-email/admin/assets/js/skyfdfe.js/wp-content/plugins/full-detail-from-email/admin/assets/js/bootstrap.min.js/wp-content/plugins/full-detail-from-email/public/assets/css/skyfdfe-style.css/wp-content/plugins/full-detail-from-email/public/assets/skyfdfe-public.js/wp-content/plugins/full-detail-from-email/admin/assets/js/skyfdfe.js/wp-content/plugins/full-detail-from-email/admin/assets/js/bootstrap.min.js/wp-content/plugins/full-detail-from-email/public/assets/skyfdfe-public.jsfull-detail-from-email/admin/assets/js/skyfdfe.js?ver=full-detail-from-email/admin/assets/js/bootstrap.min.js?ver=full-detail-from-email/public/assets/css/skyfdfe-style.css?ver=full-detail-from-email/public/assets/skyfdfe-public.js?ver=HTML / DOM Fingerprints
rowid="full_contact_api_key"name="full_contact_api_key"id="full_contact_ip_token"name="full_contact_ip_token"skyfdfe_ajax_objectskyfdfe_ajax[skyfdfe_email]