Webmention Security & Risk Analysis

wordpress.org/plugins/webmention

Enable conversation across the web.

900 active installs v5.8.1 PHP 7.4+ WP 6.2+ Updated Jun 23, 2026
indieweblinkbackpingbacktrackbackwebmention
92
A · Safe
CVEs total4
Unpatched0
Last CVEJun 30, 2026
Safety Verdict

Is Webmention Safe to Use in 2026?

Generally Safe

Score 92/100

Webmention has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

4 known CVEsLast CVE: Jun 30, 2026Updated 2mo ago
Risk Assessment

The 'webmention' plugin version 5.6.2 presents a mixed security posture. While it demonstrates good practices such as avoiding dangerous functions, file operations, and generally utilizing prepared statements for SQL, there are significant areas of concern. The plugin has 2 REST API routes exposed without permission callbacks, creating a notable attack surface that is unprotected. Additionally, only 42% of output is properly escaped, leaving a substantial portion vulnerable to cross-site scripting (XSS) attacks. The plugin's vulnerability history shows 1 medium severity CVE for Improper Neutralization of Input During Web Page Generation, which aligns with the output escaping concerns. This indicates a recurring potential for XSS vulnerabilities.

Overall, the plugin's security is hampered by the lack of robust authorization checks on its REST API endpoints and insufficient output escaping. While the absence of critical taint flows and a lack of critical or high severity unpatched CVEs are positive signs, the identified weaknesses present exploitable entry points. Users should exercise caution due to the unescaped output and unprotected REST API routes, especially given the past XSS vulnerability.

Key Concerns

  • REST API routes without permission callbacks
  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • Past medium severity CVE (XSS)
Vulnerabilities
4 published

Webmention Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
3 CVEs in 2026
2026
Patched Has unpatched

Severity Breakdown

High
2
Medium
2

4 total CVEs

CVE-2026-10513high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Webmention <= 5.8.0 - Unauthenticated Stored Cross-Site Scripting via MF2 'photo'/'url' Author Properties

Jun 30, 2026 Patched in 5.8.1 (1d)
CVE-2026-0688medium · 6.4Server-Side Request Forgery (SSRF)

Webmention <= 5.6.2 - Authenticated (Subscriber+) Server-Side Request Forgery

Apr 1, 2026 Patched in 5.7.0 (1d)
CVE-2026-0686high · 7.2Server-Side Request Forgery (SSRF)

Webmention <= 5.6.2 - Unauthenticated Blind Server-Side Request Forgery

Apr 1, 2026 Patched in 5.7.0 (1d)
WF-3d12d692-231b-4e15-a119-80fd74566af4-webmentionmedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Webmention <= 4.0.8 - Reflected Cross-Site Scripting via 'replytocom'

Mar 8, 2023 Patched in 4.0.9 (321d)
Code Analysis
Analyzed Mar 16, 2026

Webmention Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
8 prepared
Unescaped Output
38
27 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
5
Bundled Libraries
0

SQL Query Safety

80% prepared10 total queries

Output Escaping

42% escaped65 total outputs
Attack Surface
2 unprotected

Webmention Attack Surface

Entry Points2
Unprotected2

REST API Routes 2

GET/wp-json/webmention/1.0/endpointincludes\class-receiver.php:172
GET/wp-json/webmention/1.0/parseincludes\class-tools.php:41
WordPress Hooks 47
actioncomment_postincludes\class-avatar-store.php:16
actionedit_commentincludes\class-avatar-store.php:17
filterpre_get_avatar_dataincludes\class-avatar.php:15
filterget_avatar_comment_typesincludes\class-avatar.php:19
filterwp_list_comments_argsincludes\class-comment-walker.php:17
actionpre_get_commentsincludes\class-comment-walker.php:21
actioncomment_form_beforeincludes\class-comment-walker.php:24
actioncomment_form_comments_closedincludes\class-comment-walker.php:25
filtercomment_textincludes\class-comment-walker.php:112
filterquery_varsincludes\class-comment.php:17
filtertemplate_includeincludes\class-comment.php:20
filterget_comment_linkincludes\class-comment.php:22
filterget_default_comment_statusincludes\class-comment.php:25
actioncomment_form_afterincludes\class-comment.php:27
actioncomment_form_comments_closedincludes\class-comment.php:28
actionwp_headincludes\class-discovery.php:17
actiontemplate_redirectincludes\class-discovery.php:18
filterhost_metaincludes\class-discovery.php:19
filterwebfinger_user_dataincludes\class-discovery.php:20
filterwebfinger_post_dataincludes\class-discovery.php:21
filternodeinfo_dataincludes\class-discovery.php:23
filternodeinfo2_dataincludes\class-discovery.php:24
actiontemplate_redirectincludes\class-http-gone.php:17
actionrest_api_initincludes\class-receiver.php:25
filterrest_pre_serve_requestincludes\class-receiver.php:27
filterduplicate_comment_idincludes\class-receiver.php:29
filterwebmention_comment_dataincludes\class-receiver.php:32
filterwebmention_comment_dataincludes\class-receiver.php:33
filterwebmention_comment_dataincludes\class-receiver.php:36
filterpre_comment_approvedincludes\class-receiver.php:38
actionwebmention_data_errorincludes\class-receiver.php:41
actionwebmention_process_scheduleincludes\class-receiver.php:44
filterpre_comment_contentincludes\class-receiver.php:447
filterpre_comment_contentincludes\class-receiver.php:449
actioncheck_comment_floodincludes\class-receiver.php:480
actionsend_webmentionincludes\class-sender.php:20
actiondo_pingsincludes\class-sender.php:23
actionwp_trash_postincludes\class-sender.php:33
actionuntrash_postincludes\class-sender.php:34
actioncomment_postincludes\class-sender.php:36
actionwebmention_deleteincludes\class-sender.php:39
filterpre_get_postsincludes\class-sender.php:383
actionadmin_menuincludes\class-tools.php:19
actionrest_api_initincludes\class-tools.php:20
actioninitincludes\class-upgrade.php:19
filterwebmention_comment_dataincludes\class-vouch.php:19
filterhttp_request_argsincludes\debug.php:17

Scheduled Events 4

webmention_process_schedule
do_pings
webmention_delete
do_pings
Maintenance & Trust

Webmention Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJun 23, 2026
PHP min version7.4
Downloads64K

Community Trust

Rating100/100
Number of ratings8
Active installs900
Developer Profile

Webmention Developer Profile

Matthias Pfefferle

8 plugins · 3K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
81 days
View full developer profile
Detection Fingerprints

How We Detect Webmention

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webmention/build/editor-plugin/plugin.js/wp-content/plugins/webmention/css/webmention-admin.css/wp-content/plugins/webmention/css/webmention-public.css
Script Paths
/wp-content/plugins/webmention/js/webmention.js
Version Parameters
webmention/css/webmention-admin.css?ver=webmention/css/webmention-public.css?ver=webmention/js/webmention.js?ver=webmention/build/editor-plugin/plugin.js?ver=

HTML / DOM Fingerprints

CSS Classes
webmentionwebmention-postwebmention-comment
Data Attributes
data-webmention-targetdata-webmention-id
JS Globals
Webmention
REST Endpoints
/wp-json/webmention/1.0/
FAQ

Frequently Asked Questions about Webmention