Post By Email Links Security & Risk Analysis

wordpress.org/plugins/post-by-email-links

Create new posts with the 'link' post format by sending an email with a URL or link as the body.

10 active installs v0.0.3 PHP + WP 3.6+ Updated Apr 1, 2016
emaillinklinkblogpost-by-emailpost-format
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Post By Email Links Safe to Use in 2026?

Generally Safe

Score 85/100

Post By Email Links has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'post-by-email-links' plugin v0.0.3 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, reliance on prepared statements for SQL queries, and proper output escaping demonstrate adherence to secure coding practices. Furthermore, the plugin has no recorded vulnerabilities (CVEs), suggesting a history of robust security or limited attack surface that has not yet been exploited.

Despite the positive indicators, the analysis reveals a complete lack of nonce checks and capability checks. While the current entry points are reported as zero, this absence of authentication and authorization checks presents a significant potential risk should any new entry points be introduced or if existing, uncounted entry points are discovered. This creates a concern for privilege escalation or unauthorized actions if the plugin's functionality were to be expanded without proper security considerations.

In conclusion, the 'post-by-email-links' plugin appears to be secure in its current state, with no known vulnerabilities and good internal coding practices. However, the lack of defensive checks like nonces and capability checks is a notable weakness that could lead to severe security issues if the plugin's attack surface grows or if unexpected interactions with other plugins or WordPress core occur. Developers should prioritize implementing these checks to further harden the plugin.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Post By Email Links Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Post By Email Links Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Post By Email Links Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped12 total outputs
Attack Surface

Post By Email Links Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionpublish_phoneclass-post-by-email-links.php:37
actionplugins_loadedpost-by-email-links.php:46
Maintenance & Trust

Post By Email Links Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedApr 1, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Post By Email Links Developer Profile

Barry Ceelen

3 plugins · 520 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Post By Email Links

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Post By Email Links