
Recommend by mail widget Security & Risk Analysis
wordpress.org/plugins/recommend-by-mail-widgetRecommend the site or the current page to a friend by mail.
Is Recommend by mail widget Safe to Use in 2026?
Generally Safe
Score 85/100Recommend by mail widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "recommend-by-mail-widget" v1.0 plugin presents a mixed security posture. On the positive side, it has a very small attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are excellent security practices. The presence of a nonce check is also a positive indicator.
However, the static analysis reveals a significant concern with the use of the "unserialize" function. This function is inherently dangerous if used with untrusted input, as it can lead to arbitrary object injection and code execution vulnerabilities. The fact that there are no capability checks on any entry points, combined with the presence of unserialize, raises a red flag. While the taint analysis did not reveal any immediate issues, this could be due to limited analysis scope or the specific nature of the data flow. The plugin also has a clean vulnerability history, with no recorded CVEs, suggesting that the existing code, despite its potential risks, has not yet been exploited in the wild or identified as vulnerable.
In conclusion, while the plugin has a minimal attack surface and good practices in areas like SQL handling, the use of "unserialize" without evident capability checks on entry points represents a notable security risk. The lack of vulnerability history is reassuring but does not negate the inherent danger of unserializing untrusted data. Further investigation into how user-supplied data reaches the unserialize function would be prudent.
Key Concerns
- Use of unserialize without capability checks
- Improper output escaping (55% unescaped)
- Lack of capability checks on entry points
Recommend by mail widget Security Vulnerabilities
Recommend by mail widget Code Analysis
Dangerous Functions Found
Output Escaping
Recommend by mail widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Recommend by mail widget Maintenance & Trust
Maintenance Signals
Community Trust
Recommend by mail widget Alternatives
Flare
flare
Flare is a simple yet eye-catching social sharing bar that gets you followed and lets your content get shared via posts, pages, and media types.
Recommend to a friend
recommend-a-friend
Plugin that add a share to friends jQuery Lightbox to your pages or posts. Users will be able to share your content using 2 ways :
Simple Social Bar
simple-social-bar
A simple, easy to use, easy to configure social share bar that follows you down the page for sharing your posts.
Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager
custom-sidebars
Flexible sidebars for custom classic widget configurations on any page or post. Create custom sidebars with ease!
Image Widget
image-widget
A simple image widget that uses the native WordPress media manager to add image widgets to your site.
Recommend by mail widget Developer Profile
4 plugins · 530 total installs
How We Detect Recommend by mail widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
recommend_by_mail_widgetid="rbm_title"name="rbm_title"id="rbm_url"name="rbm_url"id="rbm_subject"name="rbm_subject"+7 morevar recommend_by_mail_widget