Simple Webhooks Security & Risk Analysis

wordpress.org/plugins/simple-webhooks

Enhancing WordPress functionality by adding webhooks that trigger actions when posts, pages, or custom post types are updated.

20 active installs v1.1 PHP 7.2+ WP 5.0+ Updated Mar 2, 2025
automationcustom-post-typespagespostswebhooks
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Simple Webhooks Safe to Use in 2026?

Generally Safe

Score 92/100

Simple Webhooks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "simple-webhooks" plugin v1.1 exhibits a very strong security posture based on the provided static analysis results. The absence of any identified attack surface entry points (AJAX, REST API, shortcodes, cron events) that are unprotected is a significant strength. Furthermore, the code demonstrates excellent practices by exclusively using prepared statements for SQL queries and ensuring all output is properly escaped. The lack of any dangerous functions, file operations, or critical/high-severity taint flows further reinforces this positive assessment. The plugin also has no recorded vulnerability history, which is an excellent indicator of its current security state. The only notable elements are the presence of two external HTTP requests, which, while not inherently insecure, represent potential avenues for external interaction that should be monitored for any security implications in the plugin's functionality. However, given the overall lack of identified vulnerabilities and the robust secure coding practices observed, the plugin is considered very low risk.

Vulnerabilities
None known

Simple Webhooks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Webhooks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Simple Webhooks Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_enqueue_scriptscore\setup-plugin.php:10
actionadmin_menucore\setup-plugin.php:11
actionadmin_initcore\setup-plugin.php:12
actionadmin_enqueue_scriptscore\setup-plugin.php:13
actionsave_postcore\webhook.php:74
actionbefore_delete_postcore\webhook.php:75
Maintenance & Trust

Simple Webhooks Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 2, 2025
PHP min version7.2
Downloads667

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Simple Webhooks Developer Profile

Ruslan Kolibabchuk

2 plugins · 20 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Webhooks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-webhooks/assets/css/styles.css/wp-content/plugins/simple-webhooks/assets/js/main.js
Script Paths
/wp-content/plugins/simple-webhooks/assets/js/main.js
Version Parameters
simple-webhooks/assets/css/styles.css?no-cache=simple-webhooks/assets/js/main.js?no-cache=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Simple Webhooks