Organizational Message Notifier Security & Risk Analysis

wordpress.org/plugins/organizational-message-notifier

Allows network admin to send organizational messages to blog admins. Includes read confirmation.

10 active installs v2.0.3 PHP + WP 3.5+ Updated Jul 13, 2013
messagemultisiteorganizationorganizationalsuperadmin
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Organizational Message Notifier Safe to Use in 2026?

Generally Safe

Score 85/100

Organizational Message Notifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'organizational-message-notifier' plugin v2.0.3 exhibits a generally good security posture with no known vulnerabilities or CVEs. The static analysis reveals a small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, all of which are positive indicators. Furthermore, all SQL queries utilize prepared statements, which is a critical security practice. However, there are significant concerns regarding output escaping, with only 22% of outputs being properly escaped. Additionally, the taint analysis identified 3 flows with unsanitized paths, which, while not classified as critical or high severity, still represents a potential risk of data manipulation or injection if these paths are exposed to user input.

While the plugin's history is clean, the presence of unsanitized taint flows in the current version warrants caution. The lack of nonce checks and a very low percentage of proper output escaping are the most prominent weaknesses. The fact that capability checks are present on some functions is a positive sign, but the overall security is diminished by the other identified code signals. The plugin's strengths lie in its minimal attack surface and secure SQL handling, but the weaknesses in output sanitization and taint flow management necessitate careful consideration.

Key Concerns

  • Low percentage of properly escaped output
  • Flows with unsanitized paths identified
  • No nonce checks found
Vulnerabilities
None known

Organizational Message Notifier Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Organizational Message Notifier Release Timeline

v2.0.3Current
v2.0.2
v2.0.1
v2.0
v1.5.7
v1.5.6
v1.5.5
v1.5.4
v1.5.3
v1.5.2
v1.5.1
v1.5
v1.4
v1.3
v1.2
v1.1
v1
Code Analysis
Analyzed Apr 16, 2026

Organizational Message Notifier Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
26 prepared
Unescaped Output
21
6 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared26 total queries

Output Escaping

22% escaped27 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
show_default_management_page (includes/messages-ui.php:125)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Organizational Message Notifier Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionnetwork_admin_menuincludes/messages-ui.php:17
actionadmin_menuincludes/messages-ui.php:31
actionadmin_noticesincludes/notification.php:24
actionadmin_bar_menuincludes/notification.php:40
actionnetwork_admin_menuincludes/settings-ui.php:15
actionadmin_menuincludes/settings-ui.php:30
actioninitorganizational-message-notifier.php:69
Maintenance & Trust

Organizational Message Notifier Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedJul 13, 2013
PHP min version
Downloads7K

Community Trust

Rating90/100
Number of ratings2
Active installs10
Developer Profile

Organizational Message Notifier Developer Profile

Jan Štětina

9 plugins · 200 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Organizational Message Notifier

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/organizational-message-notifier/includes/database.php/wp-content/plugins/organizational-message-notifier/includes/message-table.php/wp-content/plugins/organizational-message-notifier/includes/messages-ui.php/wp-content/plugins/organizational-message-notifier/includes/messages.php/wp-content/plugins/organizational-message-notifier/includes/notification.php/wp-content/plugins/organizational-message-notifier/includes/settings-ui.php/wp-content/plugins/organizational-message-notifier/includes/settings.php/wp-content/plugins/organizational-message-notifier/includes/zan.php

HTML / DOM Fingerprints

JS Globals
OrganizationalMessageNotifier
FAQ

Frequently Asked Questions about Organizational Message Notifier