Notify Old Blog Security & Risk Analysis

wordpress.org/plugins/notify-old-blog

Notifies when the difference between the blog last modified date and the current date exceeds a certain period.

20 active installs v1.08 PHP 8.0+ WP 4.7+ Updated Mar 29, 2026
bloglast_updatednotify
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Notify Old Blog Safe to Use in 2026?

Generally Safe

Score 100/100

Notify Old Blog has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "notify-old-blog" plugin version 1.08 exhibits a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, unsanitized taint flows, and the exclusive use of prepared statements for SQL queries indicate good development practices regarding data handling. Furthermore, the plugin demonstrates a commitment to output sanitization, with all outputs being properly escaped. The lack of file operations and external HTTP requests also reduces potential attack vectors.

While the static analysis reveals no immediate code vulnerabilities, the total absence of capability checks and nonce checks across all identified entry points (AJAX, REST API, shortcodes, cron events) is a significant concern. Although no direct entry points were found to be unprotected according to the analysis, the lack of these fundamental security mechanisms leaves the plugin vulnerable to potential attacks if any entry points are introduced or if current ones are overlooked in future development or analysis. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a history of secure development or a lack of discovery of vulnerabilities. However, this history alone should not be relied upon as a sole indicator of present security.

In conclusion, the plugin "notify-old-blog" v1.08 demonstrates excellent practices in data handling and output sanitization. Its clean vulnerability history is a positive sign. However, the complete absence of capability and nonce checks on its entry points presents a notable weakness that could be exploited if any entry points are exposed or if the plugin's functionality is expanded. This oversight requires attention to ensure robust security.

Key Concerns

  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

Notify Old Blog Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Notify Old Blog Release Timeline

v1.08Current
v1.07
v1.06
v1.05
v1.04
v1.03
v1.02
v1.01
v1.00
Code Analysis
Analyzed Apr 16, 2026

Notify Old Blog Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries
Attack Surface

Notify Old Blog Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Notify Old Blog Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 29, 2026
PHP min version8.0
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Notify Old Blog Developer Profile

Katsushi Kawamori

54 plugins · 56K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
178 days
View full developer profile
Detection Fingerprints

How We Detect Notify Old Blog

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/notify-old-blog/js/notify-old-blog.js/wp-content/plugins/notify-old-blog/css/notify-old-blog.css
Script Paths
/wp-content/plugins/notify-old-blog/js/notify-old-blog.js
Version Parameters
notify-old-blog/js/notify-old-blog.js?ver=notify-old-blog/css/notify-old-blog.css?ver=

HTML / DOM Fingerprints

JS Globals
notifyOldBlog
FAQ

Frequently Asked Questions about Notify Old Blog