Notifications to all Administrators Security & Risk Analysis

wordpress.org/plugins/notifications-to-all-administrators

Enable moderation requests and notifications by email to all administrators.

10 active installs v1.0 PHP + WP + Updated May 27, 2009
adminadministratorauthorcommentcomments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Notifications to all Administrators Safe to Use in 2026?

Generally Safe

Score 85/100

Notifications to all Administrators has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 16yr ago
Risk Assessment

The static analysis of the "notifications-to-all-administrators" v1.0 plugin reveals a remarkably clean codebase with no identified vulnerabilities or dangerous functions. The absence of SQL queries that are not properly prepared, along with 100% output escaping, demonstrates good coding practices. Furthermore, the plugin has no recorded history of CVEs, suggesting a stable and well-maintained component. The limited attack surface, with zero entry points and no unprotected handlers, is also a significant strength.

However, the complete lack of nonce checks and capability checks across all identified entry points (even though there are none reported) is a notable concern. While the current version may not expose these vulnerabilities due to its limited attack surface, it indicates a potential weakness if new functionalities are added without implementing proper authentication and authorization mechanisms. This could lead to security risks in future versions if not addressed.

In conclusion, the "notifications-to-all-administrators" v1.0 plugin currently presents a low-risk profile due to its clean code and lack of historical vulnerabilities. The primary weakness lies in the absence of security checks for authorization and integrity, which, while not exploitable in the current version, represents a potential future risk. Developers should prioritize implementing these checks if the plugin is to be expanded or maintained.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
Vulnerabilities
None known

Notifications to all Administrators Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Notifications to all Administrators Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Notifications to all Administrators Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadednotifications-to-all-administrators.php:32
filtercomment_moderation_subjectnotifications-to-all-administrators.php:67
filtercomment_notification_subjectnotifications-to-all-administrators.php:68
filterwp_mailnotifications-to-all-administrators.php:69
Maintenance & Trust

Notifications to all Administrators Maintenance & Trust

Maintenance Signals

WordPress version tested2.8
Last updatedMay 27, 2009
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Notifications to all Administrators Developer Profile

Mehdi Kabab

3 plugins · 720 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Notifications to all Administrators

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
***** BEGIN LICENSE BLOCK ***** ***** END LICENSE BLOCK *****
FAQ

Frequently Asked Questions about Notifications to all Administrators