Webmaster Spelling Notifications Security & Risk Analysis

wordpress.org/plugins/gourl-spelling-notifications

Plugin allows site visitors to send reports to the webmaster/owner about any spelling or grammatical errors. Spelling checker on your website.

100 active installs v1.1.2 PHP + WP 3.5+ Updated Jul 13, 2021
gourlgrammarspell-checkerspellingspelling-checker
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Webmaster Spelling Notifications Safe to Use in 2026?

Generally Safe

Score 85/100

Webmaster Spelling Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "gourl-spelling-notifications" plugin v1.1.2 exhibits a strong security posture in several key areas, particularly regarding its handling of SQL queries and output escaping. The static analysis shows a high percentage of properly escaped outputs and exclusively uses prepared statements for SQL, indicating good coding practices to prevent common injection vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a limited attack surface.

However, the analysis also reveals some concerning aspects. The taint analysis identified four flows with unsanitized paths, all of which were deemed to have no severity. While this is positive, the mere presence of unsanitized paths warrants attention and suggests potential for future vulnerabilities if code logic changes. More critically, the plugin lacks any nonce checks or capability checks. This is a significant concern, as it means that any entry point, if one were to exist, would not be protected by WordPress's built-in security mechanisms, potentially allowing unauthorized actions.

The vulnerability history is clean, with no known CVEs recorded. This, combined with the generally good coding practices, suggests a plugin that has historically been well-maintained from a security perspective. However, the lack of protective measures like nonce and capability checks is a persistent weakness that could be exploited if an attack vector were discovered. In conclusion, while the plugin demonstrates strengths in data handling and avoids common pitfalls, the absence of crucial authorization and integrity checks presents a notable risk.

Key Concerns

  • Flows with unsanitized paths
  • Missing nonce checks
  • Missing capability checks
  • Low percentage of properly escaped outputs
Vulnerabilities
None known

Webmaster Spelling Notifications Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Webmaster Spelling Notifications Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
38 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

90% escaped42 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
gourl_spelling_load (gourl_spelling.php:35)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Webmaster Spelling Notifications Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedgourl_spelling.php:24
actionplugins_loadedgourl_spelling.php:26
actionadmin_footer_textgourl_spelling.php:87
actionadmin_menugourl_spelling.php:90
actionadmin_headgourl_spelling.php:91
actionwp_headgourl_spelling.php:95
filterplugin_action_linksgourl_spelling.php:100
actionparse_requestgourl_spelling.php:102
Maintenance & Trust

Webmaster Spelling Notifications Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedJul 13, 2021
PHP min version
Downloads101K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Webmaster Spelling Notifications Developer Profile

gourl

11 plugins · 2K total installs

67
trust score
Avg Security Score
83/100
Avg Patch Time
1910 days
View full developer profile
Detection Fingerprints

How We Detect Webmaster Spelling Notifications

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gourl-spelling-notifications/gourl_spelling.js/wp-content/plugins/gourl-spelling-notifications/gourl_spelling.css/wp-content/plugins/gourl-spelling-notifications/gourl_spelling2.css
Version Parameters
/gourl_spelling.js?ver=/gourl_spelling.css?ver=/gourl_spelling2.css?ver=

HTML / DOM Fingerprints

Data Attributes
spl_pathspl_txt1spl_txt2
JS Globals
spl_pathspl_txt1spl_txt2
FAQ

Frequently Asked Questions about Webmaster Spelling Notifications