
Publish Post Email Notification Security & Risk Analysis
wordpress.org/plugins/publish-post-email-notificationPublish post notification is plugin which will send an automatic email to its author when the post is published and approved by WP admin.
Is Publish Post Email Notification Safe to Use in 2026?
Generally Safe
Score 99/100Publish Post Email Notification has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "publish-post-email-notification" v1.0.2.4 exhibits a mixed security posture. On the positive side, the static analysis indicates a small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. The code also demonstrates good practices regarding SQL queries, exclusively using prepared statements, and includes a nonce check. However, there are significant concerns regarding output escaping, with only 56% of outputs being properly escaped, leaving a substantial portion vulnerable to Cross-Site Scripting (XSS).
The vulnerability history reveals a concerning pattern. The plugin has two known medium-severity CVEs, one of which was recently discovered (2025-03-27). While currently unpatched vulnerabilities are zero, the existence of past CSRF and XSS vulnerabilities indicates a recurring weakness in input sanitization and output escaping, which aligns with the static analysis findings of imperfect output escaping.
In conclusion, while the plugin has strengths in its limited attack surface and secure SQL handling, the significant percentage of unescaped output and a history of XSS and CSRF vulnerabilities present a notable risk. Users should be aware of the potential for XSS attacks. The absence of capability checks on any identified entry points (though none are explicitly listed as unprotected) is also a potential area for further investigation if any entry points are discovered in deeper analysis.
Key Concerns
- Insufficient output escaping (44% unescaped)
- Lack of capability checks on entry points
- History of medium severity CVEs (2 total)
Publish Post Email Notification Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
publish post email notification <= 1.0.2.3 - Cross-Site Request Forgery
wordpress publish post email notification <= 1.0.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Publish Post Email Notification Code Analysis
Output Escaping
Publish Post Email Notification Attack Surface
WordPress Hooks 5
Maintenance & Trust
Publish Post Email Notification Maintenance & Trust
Maintenance Signals
Community Trust
Publish Post Email Notification Alternatives
No alternatives data available yet.
Publish Post Email Notification Developer Profile
19 plugins · 23K total installs
How We Detect Publish Post Email Notification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/publish-post-email-notification/css/styles.css/wp-content/plugins/publish-post-email-notification/js/jqueryValidate.jspublish-post-email-notification/css/styles.css?ver=publish-post-email-notification/js/jqueryValidate.js?ver=