
Unconfirmed Security & Risk Analysis
wordpress.org/plugins/unconfirmedAllows WordPress admins to manage unactivated users, by activating them manually, deleting their pending registrations, or resending the activation em …
Is Unconfirmed Safe to Use in 2026?
Mostly Safe
Score 84/100Unconfirmed is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.
The "unconfirmed" plugin v1.3.7 exhibits a strong static analysis profile, with no identified entry points lacking authentication, no dangerous functions, and all SQL queries utilizing prepared statements. Furthermore, all output is properly escaped, there are no file operations or external HTTP requests, and the plugin demonstrates a good use of nonce and capability checks. Taint analysis also shows no critical or high severity flows with unsanitized paths. This indicates a developer who has implemented many robust security practices.
However, the plugin does have a history of one high severity vulnerability, specifically Cross-Site Scripting, recorded in 2014. While this vulnerability is marked as patched, the presence of past high-severity issues, even if resolved, warrants attention. It suggests a potential for complex vulnerabilities to arise if not continually monitored and updated. The lack of any recent vulnerabilities is positive, but the past high-severity finding is a reminder that past issues can sometimes resurface or indicate areas where the code might be more susceptible.
In conclusion, the "unconfirmed" plugin v1.3.7 presents a generally good security posture due to its excellent static analysis results and current lack of unpatched vulnerabilities. The developer's adherence to secure coding practices like prepared statements and output escaping is commendable. The primary concern stems from the historical high-severity XSS vulnerability, which, despite being patched, serves as a flag for potential future risks in similar code areas. Users should remain vigilant for any future updates or security advisories related to this plugin.
Key Concerns
- High severity vulnerability in history
Unconfirmed Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Unconfirmed < 1.2.5 - Reflected Cross-Site Scripting
Unconfirmed Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Unconfirmed Attack Surface
WordPress Hooks 4
Maintenance & Trust
Unconfirmed Maintenance & Trust
Maintenance Signals
Community Trust
Unconfirmed Alternatives
Network Mass Email
network-mass-email
Allows network admins to send a manually created notification email to all registered users based on user role.
Metro Share Widget
metro-share-widget
Add Metro style social share widget to your sidebar. 5 most popular social networks supported
Network Username Restrictions Override
network-username-restrictions-override
Override restrictions on WordPress network usernames.
Plugin Activation Status
plugin-activation-status
Scans a multisite or multi-network installation to identify all plugins that are active or not.
User Activation Keys
user-activation-keys
A Multisite Network plugin for user activation key removal or approval.
Unconfirmed Developer Profile
27 plugins · 12K total installs
How We Detect Unconfirmed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/unconfirmed/css/style.cssunconfirmed/css/style.css?ver=