
TG Email Protection Security & Risk Analysis
wordpress.org/plugins/tg-email-protectionProtect email addresses from being harvested by spammers and spambots, obfuscating them. Your visitors can still see email addresses.
Is TG Email Protection Safe to Use in 2026?
Generally Safe
Score 85/100TG Email Protection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The tg-email-protection v1.0 plugin exhibits a strong security posture in several key areas, particularly regarding its handling of SQL queries and lack of external HTTP requests. The absence of any recorded vulnerabilities or CVEs in its history is a positive indicator, suggesting a history of responsible development or a lack of historical scrutiny. The static analysis also shows a minimal attack surface with no reported dangerous functions or file operations.
However, a significant concern arises from the complete lack of output escaping in all identified output points. This presents a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the WordPress environment. Furthermore, the absence of nonce and capability checks across all entry points, including its sole shortcode, means that any user, regardless of their privileges, could potentially trigger the plugin's functionality, opening it up to unauthorized actions or information disclosure.
While the plugin has a clean vulnerability history and good practices in data handling (SQL prepared statements), the critical findings of unescaped output and missing authorization checks on its shortcode introduce substantial security weaknesses. These issues require immediate attention to mitigate potential XSS and unauthorized access risks.
Key Concerns
- No output escaping
- No nonce checks on shortcode
- No capability checks on shortcode
TG Email Protection Security Vulnerabilities
TG Email Protection Code Analysis
Output Escaping
TG Email Protection Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
TG Email Protection Maintenance & Trust
Maintenance Signals
Community Trust
TG Email Protection Alternatives
HumansNotBots – Easy, Accessible Email Cloaker
humansnotbots
"email AT address DOT com" (without quotes) is converted to a clickable version of email@address.com if JavaScript is enabled.
WhoKnew Shield — Contact Obfuscation & Bot Protection
whoknew-shield
Stop spam bots from harvesting emails, phones & addresses. Dual-layer protection with auto-detection.
Email Address Obfuscation
email-address-obfuscation
Email Address Obfuscation prevents email harvesting by hiding email address appearing in your pages, while remaining visible to your site visitors.
Pixeline's Email Protector
pixelines-email-protector
Write email addresses without worrying about spambots and email harvesters.
Email No Bot – Prevent bots from detecting emails
email-no-bot
Humans will see the email address on your page, but robots will not.
TG Email Protection Developer Profile
3 plugins · 340 total installs
How We Detect TG Email Protection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[tgemail][/tgemail]