Unconfirmed Security & Risk Analysis

wordpress.org/plugins/unconfirmed

Allows WordPress admins to manage unactivated users, by activating them manually, deleting their pending registrations, or resending the activation em …

2K active installs v1.3.7 PHP + WP 3.1+ Updated Dec 4, 2023
activateactivationemailmultisitenetwork
84
B · Generally Safe
CVEs total1
Unpatched0
Last CVEApr 11, 2014
Safety Verdict

Is Unconfirmed Safe to Use in 2026?

Mostly Safe

Score 84/100

Unconfirmed is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVELast CVE: Apr 11, 2014Updated 2yr ago
Risk Assessment

The "unconfirmed" plugin v1.3.7 exhibits a strong static analysis profile, with no identified entry points lacking authentication, no dangerous functions, and all SQL queries utilizing prepared statements. Furthermore, all output is properly escaped, there are no file operations or external HTTP requests, and the plugin demonstrates a good use of nonce and capability checks. Taint analysis also shows no critical or high severity flows with unsanitized paths. This indicates a developer who has implemented many robust security practices.

However, the plugin does have a history of one high severity vulnerability, specifically Cross-Site Scripting, recorded in 2014. While this vulnerability is marked as patched, the presence of past high-severity issues, even if resolved, warrants attention. It suggests a potential for complex vulnerabilities to arise if not continually monitored and updated. The lack of any recent vulnerabilities is positive, but the past high-severity finding is a reminder that past issues can sometimes resurface or indicate areas where the code might be more susceptible.

In conclusion, the "unconfirmed" plugin v1.3.7 presents a generally good security posture due to its excellent static analysis results and current lack of unpatched vulnerabilities. The developer's adherence to secure coding practices like prepared statements and output escaping is commendable. The primary concern stems from the historical high-severity XSS vulnerability, which, despite being patched, serves as a flag for potential future risks in similar code areas. Users should remain vigilant for any future updates or security advisories related to this plugin.

Key Concerns

  • High severity vulnerability in history
Vulnerabilities
1

Unconfirmed Security Vulnerabilities

CVEs by Year

1 CVE in 2014
2014
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2014-100018high · 7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Unconfirmed < 1.2.5 - Reflected Cross-Site Scripting

Apr 11, 2014 Patched in 1.2.5 (3574d)
Code Analysis
Analyzed Mar 16, 2026

Unconfirmed Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
22 prepared
Unescaped Output
0
37 escaped
Nonce Checks
6
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

96% prepared23 total queries

Output Escaping

100% escaped37 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
admin_panel_main (includes\class-bbg-unconfirmed.php:835)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Unconfirmed Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterbbg_cpt_pag_add_argsincludes\class-bbg-unconfirmed.php:65
filterboones_sortable_columns_keys_to_removeincludes\class-bbg-unconfirmed.php:67
filtermap_meta_capincludes\class-bbg-unconfirmed.php:69
actionplugins_loadedunconfirmed.php:31
Maintenance & Trust

Unconfirmed Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedDec 4, 2023
PHP min version
Downloads246K

Community Trust

Rating90/100
Number of ratings47
Active installs2K
Developer Profile

Unconfirmed Developer Profile

Boone Gorges

27 plugins · 12K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
1864 days
View full developer profile
Detection Fingerprints

How We Detect Unconfirmed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/unconfirmed/css/style.css
Version Parameters
unconfirmed/css/style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Unconfirmed