
Webmention Security & Risk Analysis
wordpress.org/plugins/webmentionEnable conversation across the web.
Is Webmention Safe to Use in 2026?
Generally Safe
Score 100/100Webmention has a strong security track record. Known vulnerabilities have been patched promptly.
The 'webmention' plugin version 5.6.2 presents a mixed security posture. While it demonstrates good practices such as avoiding dangerous functions, file operations, and generally utilizing prepared statements for SQL, there are significant areas of concern. The plugin has 2 REST API routes exposed without permission callbacks, creating a notable attack surface that is unprotected. Additionally, only 42% of output is properly escaped, leaving a substantial portion vulnerable to cross-site scripting (XSS) attacks. The plugin's vulnerability history shows 1 medium severity CVE for Improper Neutralization of Input During Web Page Generation, which aligns with the output escaping concerns. This indicates a recurring potential for XSS vulnerabilities.
Overall, the plugin's security is hampered by the lack of robust authorization checks on its REST API endpoints and insufficient output escaping. While the absence of critical taint flows and a lack of critical or high severity unpatched CVEs are positive signs, the identified weaknesses present exploitable entry points. Users should exercise caution due to the unescaped output and unprotected REST API routes, especially given the past XSS vulnerability.
Key Concerns
- REST API routes without permission callbacks
- Low percentage of properly escaped output
- No nonce checks on entry points
- Past medium severity CVE (XSS)
Webmention Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Webmention <= 4.0.8 - Reflected Cross-Site Scripting via 'replytocom'
Webmention Code Analysis
SQL Query Safety
Output Escaping
Webmention Attack Surface
REST API Routes 2
WordPress Hooks 47
Scheduled Events 4
Maintenance & Trust
Webmention Maintenance & Trust
Maintenance Signals
Community Trust
Webmention Alternatives
No Self Ping
no-self-ping
Keeps WordPress from sending pings to your own site.
IndieWeb
indieweb
IndieWeb for WordPress!
Hide Trackbacks
hide-trackbacks
Prevents trackbacks and pingbacks from showing up as comments on posts.
Really Simple Disable Comments
really-simple-disable-comments
Effortlessly disable all comments and trackback functionality across your entire WordPress site by activating this plugin.
IndieBlocks
indieblocks
Use blocks, and, optionally, "short-form" post types to easily "IndieWebify" your WordPress site.
Webmention Developer Profile
8 plugins · 3K total installs
How We Detect Webmention
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webmention/build/editor-plugin/plugin.js/wp-content/plugins/webmention/css/webmention-admin.css/wp-content/plugins/webmention/css/webmention-public.css/wp-content/plugins/webmention/js/webmention.jswebmention/css/webmention-admin.css?ver=webmention/css/webmention-public.css?ver=webmention/js/webmention.js?ver=webmention/build/editor-plugin/plugin.js?ver=HTML / DOM Fingerprints
webmentionwebmention-postwebmention-commentdata-webmention-targetdata-webmention-idWebmention/wp-json/webmention/1.0/