numly Numbers Security & Risk Analysis

wordpress.org/plugins/numly-numbers

The plugin registers your copyright with Numly and returns the Numly Number (ESN), barcode, and verification links to your blog post automatically.

10 active installs v2.6 PHP + WP 3.0+ Updated Nov 25, 2015
electronic-serial-numbersesbnesnnumly
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is numly Numbers Safe to Use in 2026?

Generally Safe

Score 85/100

numly Numbers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The "numly-numbers" plugin version 2.6 exhibits a mixed security posture. On the positive side, the static analysis shows no obvious direct attack vectors like unprotected AJAX handlers, REST API routes, or shortcodes. Furthermore, all SQL queries are prepared, which is a strong security practice. However, there are significant concerns regarding output escaping, with 0% of outputs being properly escaped. This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in users' browsers. The taint analysis revealing two flows with unsanitized paths, though not classified as critical or high, is still a red flag and indicates potential for unexpected behavior or security issues if these paths involve user-supplied data. The plugin's history of zero known vulnerabilities is a positive sign, suggesting past development efforts have been secure or issues have been promptly addressed. However, this clean history should not overshadow the identified code-level risks, particularly the widespread lack of output escaping.

Key Concerns

  • Output escaping is not implemented
  • Taint flows with unsanitized paths
Vulnerabilities
None known

numly Numbers Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

numly Numbers Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
numly_options_page (numly.php:92)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

numly Numbers Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionadmin_menunumly.php:258
actionpublish_postnumly.php:259
Maintenance & Trust

numly Numbers Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedNov 25, 2015
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

numly Numbers Developer Profile

Scott Grayban

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect numly Numbers

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/numly-numbers/numly.css/wp-content/plugins/numly-numbers/numly_options.js/wp-content/plugins/numly-numbers/numly.js/wp-content/plugins/numly-numbers/css/style.css
Script Paths
/wp-content/plugins/numly-numbers/numly_options.js/wp-content/plugins/numly-numbers/numly.js
Version Parameters
numly.css?ver=numly_options.js?ver=numly.js?ver=style.css?ver=

HTML / DOM Fingerprints

CSS Classes
numly-output
HTML Comments
<!--Creative Commons License--><!--/Creative Commons License--><!-- Creative Commons Public Domain --><!-- /Creative Commons Public Domain -->
Data Attributes
rel="license"alt="numly"alt="Creative Commons License"alt="Public Domain Dedication"
Shortcode Output
<div class="numly-output"><img align="bottom" alt="numly" src="http://numly.com/images/numly.png" border="0"/><iframe height="50" width="400" src="http://www.numly.com/numly/barcode.asp?code=&height=30" name="munly1" id="numly1" scrolling="no" frameborder="0"/></iframe>
FAQ

Frequently Asked Questions about numly Numbers