
Notifier and IP Blocker Security & Risk Analysis
wordpress.org/plugins/notifier-and-ip-blockerNotify a user about when he sent comment or form via Contact Form 7 and automatically blocked spammer IP by notifier users.
Is Notifier and IP Blocker Safe to Use in 2026?
Generally Safe
Score 85/100Notifier and IP Blocker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "notifier-and-ip-blocker" v1.0 plugin presents a mixed security posture. While the plugin has a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected, and boasts a lack of known vulnerabilities or CVEs, several concerning code signals indicate potential weaknesses. Specifically, the 50% of SQL queries not using prepared statements is a significant concern, as is the extremely low 12% rate of properly escaped output. This suggests a high likelihood of SQL injection and cross-site scripting (XSS) vulnerabilities, respectively.
The taint analysis revealing two high-severity flows with unsanitized paths further exacerbates these concerns. These flows, combined with the insufficient output escaping and raw SQL queries, point to critical areas where attacker-controlled data could be processed or rendered without proper validation or sanitization, potentially leading to serious security breaches. The absence of capability checks is also a notable omission, which, when combined with other weaknesses, could allow unauthorized actions.
Key Concerns
- SQL queries not using prepared statements
- Low rate of properly escaped output
- High severity taint flows with unsanitized paths
- No capability checks found
Notifier and IP Blocker Security Vulnerabilities
Notifier and IP Blocker Release Timeline
Notifier and IP Blocker Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Notifier and IP Blocker Attack Surface
WordPress Hooks 4
Maintenance & Trust
Notifier and IP Blocker Maintenance & Trust
Maintenance Signals
Community Trust
Notifier and IP Blocker Alternatives
WP User Notifier
wp-user-notifier
Notify a user about when he sent comment or form via Contact Form 7
WP Comment Policy Checkbox
wp-comment-policy-checkbox
Add a checkbox and custom text to the comment forms so that the user can be informed and give consent to the web's privacy policy.
Comment Form WP – Customize Default Comment Form
comment-form-wp
Comment Form WP is a Default comment form customize/modify WordPress Plugin. You can add/change/remove your website comment form fields, texts.
Custom Comment
customcomment
This plugin lets you define more fields for comment to let your visitors include their facebook, twitter and ... in their comments
AdSignalPro
adsignalpro
Google AdWords Click Fraud, Attack Notifications: Real-time data, sharp analysis.
Notifier and IP Blocker Developer Profile
2 plugins · 20 total installs
How We Detect Notifier and IP Blocker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/notifier-and-ip-blocker/assets/css/admin-naipb-styles.css/wp-content/plugins/notifier-and-ip-blocker/assets/js/admin-naipb-scripts.js/wp-content/plugins/notifier-and-ip-blocker/assets/js/admin-naipb-scripts.jsnotifier-and-ip-blocker/assets/css/admin-naipb-styles.css?ver=notifier-and-ip-blocker/assets/js/admin-naipb-scripts.js?ver=HTML / DOM Fingerprints
naipb-settings-wrapnaipb-settings-sectionnotifier-and-ip-blockerdata-naipb-slugnaipb_admin_params[name][email][url][sitename]