Webhook for Discord Security & Risk Analysis

wordpress.org/plugins/webhook-discord

This plugin allows you to easily notify the Discord group when you post an article.

500 active installs v1.2.2 PHP 7.4+ WP 4.4+ Updated Oct 17, 2023
chatdiscordwebhook
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Webhook for Discord Safe to Use in 2026?

Generally Safe

Score 85/100

Webhook for Discord has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "webhook-discord" v1.2.2 plugin exhibits a generally positive security posture, primarily due to the absence of identified vulnerabilities in its history and a clean static analysis report. The plugin correctly utilizes prepared statements for all SQL queries, and it appears to handle output escaping reasonably well, with 74% of outputs properly escaped, which is a decent but not perfect score. The limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected, is also a significant strength. The presence of a capability check and the absence of dangerous functions or file operations further contribute to its secure design. However, the plugin does make two external HTTP requests, which could potentially be a vector for issues if the target endpoint is compromised or if data is not properly handled before transmission. Additionally, the absence of nonce checks on any potential entry points, even though none are explicitly identified, could be a concern if new entry points are added in the future without adequate protection. The vulnerability history being completely clean is a strong indicator of past diligence in development.

Key Concerns

  • External HTTP requests present
  • Output escaping not 100% effective
Vulnerabilities
None known

Webhook for Discord Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Webhook for Discord Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
32 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

74% escaped43 total outputs
Attack Surface

Webhook for Discord Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_menuincludes\class-discord-webhook-admin.php:22
actionadmin_initincludes\class-discord-webhook-admin.php:23
actionadmin_initincludes\class-discord-webhook-admin.php:24
actionwpcf7_before_send_mailincludes\class-discord-webhook-contact-form-7.php:21
actionadmin_initincludes\class-discord-webhook-dank-meme.php:19
actiongform_entry_createdincludes\class-discord-webhook-gravityforms.php:21
actiongrunion_pre_message_sentincludes\class-discord-webhook-jetpack-contact-form.php:21
actionpublish_postincludes\class-discord-webhook-post.php:21
actionwoocommerce_process_product_metaincludes\class-discord-webhook-woocommerce.php:22
actionwoocommerce_checkout_update_order_metaincludes\class-discord-webhook-woocommerce.php:26
Maintenance & Trust

Webhook for Discord Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedOct 17, 2023
PHP min version7.4
Downloads6K

Community Trust

Rating100/100
Number of ratings3
Active installs500
Developer Profile

Webhook for Discord Developer Profile

monster2408

1 plugin · 500 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Webhook for Discord

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webhook-discord/assets/css/style.css/wp-content/plugins/webhook-discord/assets/js/script.js
Script Paths
/wp-content/plugins/webhook-discord/assets/js/script.js
Version Parameters
webhook-discord/assets/css/style.css?ver=webhook-discord/assets/js/script.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- THIS IS THE DISCORD WEBHOOK PLUGIN FOR WORDPRESS -->
FAQ

Frequently Asked Questions about Webhook for Discord