Html New User Notification Security & Risk Analysis

wordpress.org/plugins/html-new-user-notification-email

This plugin gives you option for sending html new user notification email.

30 active installs v1.1 PHP + WP 3.0.1+ Updated Jun 16, 2015
e-mailemailemail-logmailsend
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Html New User Notification Safe to Use in 2026?

Generally Safe

Score 85/100

Html New User Notification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "html-new-user-notification-email" plugin v1.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no directly exposed entry points such as AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. Furthermore, all SQL queries utilize prepared statements, and there are no observed file operations or external HTTP requests, which are common vectors for attack. The absence of known CVEs and a clean vulnerability history are also strengths.

However, a significant concern arises from the code analysis regarding output escaping. With 8 total outputs and 0% properly escaped, this presents a substantial risk of cross-site scripting (XSS) vulnerabilities. Any user-supplied data or dynamic content rendered by the plugin that is not properly escaped could be exploited by an attacker to inject malicious scripts into the user's browser.

In conclusion, while the plugin benefits from a lack of traditional attack surface and secure database interactions, the severe lack of output escaping is a critical weakness that needs immediate attention. The vulnerability history is currently clean, but this could be due to a lack of rigorous testing or exploitation of the unescaped outputs. Addressing the output escaping is paramount to mitigating the risk of XSS attacks.

Key Concerns

  • 0% of outputs are properly escaped
Vulnerabilities
None known

Html New User Notification Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Html New User Notification Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Html New User Notification Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

Html New User Notification Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initab-index.php:15
actionadmin_menuab-index.php:25
filterwp_mail_content_typeab-index.php:74
actionadmin_initadmin/ab-options.php:90
Maintenance & Trust

Html New User Notification Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJun 16, 2015
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings6
Active installs30
Developer Profile

Html New User Notification Developer Profile

Abhishek Kumar

2 plugins · 430 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Html New User Notification

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/html-new-user-notification-email/css/ab-html-un.css
Version Parameters
html-new-user-notification-email/css/ab-html-un.css?ver=

HTML / DOM Fingerprints

Shortcode Output
[ab-display-name][ab-user-login][ab-user-password][ab-user-email]
FAQ

Frequently Asked Questions about Html New User Notification