Notify All Admins on Comment Security & Risk Analysis

wordpress.org/plugins/notify-all-admins-on-comment

A simple plugin that ensures all site administrators are notified of new comments, not just the main site admin.

0 active installs v1.0.1 PHP 7.0+ WP 5.0+ Updated Unknown
admincommentsemailnotifications
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Notify All Admins on Comment Safe to Use in 2026?

Generally Safe

Score 100/100

Notify All Admins on Comment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "notify-all-admins-on-comment" plugin v1.0.1 exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified attack surface points, dangerous functions, or unescaped output, coupled with the exclusive use of prepared statements for SQL queries, indicates robust development practices. Furthermore, the lack of any recorded vulnerabilities, including critical or high-severity ones, suggests a history of secure code and diligent maintenance.

While the code analysis shows no immediate threats, the complete absence of capability checks and nonce checks across all entry points, even though the static analysis reports zero entry points, is a potential area of concern. If any entry points were to be introduced or discovered in future versions, their lack of authorization checks would present a significant risk. The absence of any taint analysis results, while positive, could also be due to the limited attack surface being analyzed or the specific methods used in the analysis.

In conclusion, the plugin currently appears highly secure due to its clean code and unblemished vulnerability record. However, the lack of explicit authorization checks on potential future entry points warrants careful consideration. This suggests the developers have prioritized minimizing the attack surface, but a proactive approach to securing any new or existing functionalities with proper authorization checks would further solidify its security.

Key Concerns

  • No capability checks detected
  • No nonce checks detected
Vulnerabilities
None known

Notify All Admins on Comment Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Notify All Admins on Comment Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Notify All Admins on Comment Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioncomment_postnotify-all-admins-on-comment.php:19
Maintenance & Trust

Notify All Admins on Comment Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.0
Downloads340

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Notify All Admins on Comment Developer Profile

hugowporg

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Notify All Admins on Comment

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Notify All Admins on Comment