
Webmaster Spelling Notifications Security & Risk Analysis
wordpress.org/plugins/gourl-spelling-notificationsPlugin allows site visitors to send reports to the webmaster/owner about any spelling or grammatical errors. Spelling checker on your website.
Is Webmaster Spelling Notifications Safe to Use in 2026?
Generally Safe
Score 85/100Webmaster Spelling Notifications has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gourl-spelling-notifications" plugin v1.1.2 exhibits a strong security posture in several key areas, particularly regarding its handling of SQL queries and output escaping. The static analysis shows a high percentage of properly escaped outputs and exclusively uses prepared statements for SQL, indicating good coding practices to prevent common injection vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a limited attack surface.
However, the analysis also reveals some concerning aspects. The taint analysis identified four flows with unsanitized paths, all of which were deemed to have no severity. While this is positive, the mere presence of unsanitized paths warrants attention and suggests potential for future vulnerabilities if code logic changes. More critically, the plugin lacks any nonce checks or capability checks. This is a significant concern, as it means that any entry point, if one were to exist, would not be protected by WordPress's built-in security mechanisms, potentially allowing unauthorized actions.
The vulnerability history is clean, with no known CVEs recorded. This, combined with the generally good coding practices, suggests a plugin that has historically been well-maintained from a security perspective. However, the lack of protective measures like nonce and capability checks is a persistent weakness that could be exploited if an attack vector were discovered. In conclusion, while the plugin demonstrates strengths in data handling and avoids common pitfalls, the absence of crucial authorization and integrity checks presents a notable risk.
Key Concerns
- Flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
- Low percentage of properly escaped outputs
Webmaster Spelling Notifications Security Vulnerabilities
Webmaster Spelling Notifications Code Analysis
Output Escaping
Data Flow Analysis
Webmaster Spelling Notifications Attack Surface
WordPress Hooks 8
Maintenance & Trust
Webmaster Spelling Notifications Maintenance & Trust
Maintenance Signals
Community Trust
Webmaster Spelling Notifications Alternatives
TinyMCE Spellcheck
tinymce-spellcheck
TinyMCE Spellcheck adds the spellcheck button back to the editor in WordPress 3.6 and up.
Perfect Tense – Spelling and Grammar Checker
perfect-tense
Perfect Tense is an AI-powered, spelling and grammar corrector. Perfect Tense will automatically detect and fix mistakes, proofread entire blog posts, …
FLiP – Portuguese Proofing Tools
flip
IMPORTANT: The free version of the plugin only checks the spelling of the texts in the pre 1990 Spelling Reform and doesn’t present any suggestions fo …
Qalam Arabic AI Writing Assistant Plugin | Qalam
qalam
Qalam plugin for WordPress adds AI based grammar, spell check, and Tashkeel "Diacritization" capabilities to your website content in Arabic Language.
Orphans
sierotki
Supports the grammar rule for orphan words at the end of a line.
Webmaster Spelling Notifications Developer Profile
11 plugins · 2K total installs
How We Detect Webmaster Spelling Notifications
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gourl-spelling-notifications/gourl_spelling.js/wp-content/plugins/gourl-spelling-notifications/gourl_spelling.css/wp-content/plugins/gourl-spelling-notifications/gourl_spelling2.css/gourl_spelling.js?ver=/gourl_spelling.css?ver=/gourl_spelling2.css?ver=HTML / DOM Fingerprints
spl_pathspl_txt1spl_txt2spl_pathspl_txt1spl_txt2