Post Notification by Email Security & Risk Analysis

wordpress.org/plugins/notify-users-e-mail

Send an email to all users whenever a new post is published on your WordPress.

2K active installs v4.1.3 PHP + WP 3.0+ Updated Jun 21, 2019
emailsnew-postsnotificationpostusers
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post Notification by Email Safe to Use in 2026?

Generally Safe

Score 85/100

Post Notification by Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "notify-users-e-mail" plugin v4.1.3 exhibits a strong security posture based on the static analysis and vulnerability history. The plugin has a zero attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication or permission checks. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests, coupled with the use of prepared statements for all SQL queries, indicates good development practices. The presence of a nonce check and a capability check also contributes positively to its security. The vulnerability history is completely clean, with no known CVEs, which is a significant strength. However, a notable concern is the low percentage of properly escaped output (33%). This indicates a potential risk for cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed. While the taint analysis shows no critical or high-severity flows, the unescaped output is a real, albeit lower-severity, concern that should not be overlooked.

Key Concerns

  • Low percentage of properly escaped output
  • Bundled outdated library: Select2 v3.5.2
Vulnerabilities
None known

Post Notification by Email Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Post Notification by Email Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
20
10 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select23.5.2

SQL Query Safety

100% prepared2 total queries

Output Escaping

33% escaped30 total outputs
Attack Surface

Post Notification by Email Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_menuincludes\class-notify-users-e-mail-admin.php:31
actionadmin_menuincludes\class-notify-users-e-mail-admin.php:34
actionadmin_menuincludes\class-notify-users-e-mail-admin.php:37
actionadmin_initincludes\class-notify-users-e-mail-admin.php:40
actionadmin_enqueue_scriptsincludes\class-notify-users-e-mail-admin.php:43
actioninitnotify-users-e-mail.php:61
actionwpmu_new_blognotify-users-e-mail.php:64
actionadmin_initnotify-users-e-mail.php:71
actiontransition_post_statusnotify-users-e-mail.php:75
actionwp_insert_commentnotify-users-e-mail.php:78
actiontransition_comment_statusnotify-users-e-mail.php:79
actionplugins_loadednotify-users-e-mail.php:547
Maintenance & Trust

Post Notification by Email Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedJun 21, 2019
PHP min version
Downloads46K

Community Trust

Rating96/100
Number of ratings24
Active installs2K
Developer Profile

Post Notification by Email Developer Profile

Valerio Souza

8 plugins · 3K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post Notification by Email

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/notify-users-e-mail/css/notify.css/wp-content/plugins/notify-users-e-mail/js/notify.js
Version Parameters
notify-users-e-mail/css/notify.css?ver=notify-users-e-mail/js/notify.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Post Notification by Email