
WhoKnew Shield — Contact Obfuscation & Bot Protection Security & Risk Analysis
wordpress.org/plugins/whoknew-shieldStop spam bots from harvesting emails, phones & addresses. Dual-layer protection with auto-detection.
Is WhoKnew Shield — Contact Obfuscation & Bot Protection Safe to Use in 2026?
Generally Safe
Score 100/100WhoKnew Shield — Contact Obfuscation & Bot Protection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The whoknew-shield v2.0.1 plugin exhibits a very strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, raw SQL queries, and external HTTP requests are significant strengths. Furthermore, the high percentage of properly escaped output (99%) and the presence of nonce and capability checks on all identified entry points suggest a well-hardened codebase. The plugin also has no recorded vulnerability history, indicating a sustained commitment to security or a lack of past exploits, both positive indicators.
While the static analysis shows an attack surface of 12 entry points, all are protected by authentication or permission checks. The taint analysis revealing zero flows with unsanitized paths is particularly encouraging, as this often indicates potential for critical vulnerabilities like RCE or SQL injection. The only area that could be marginally improved is ensuring 100% output escaping, though 99% is generally considered very good.
In conclusion, whoknew-shield v2.0.1 appears to be a secure plugin. Its developers have implemented robust security practices, and there is no evidence of past vulnerabilities or concerning code patterns in the static analysis. The plugin's security posture is excellent, with minimal to no apparent risks.
WhoKnew Shield — Contact Obfuscation & Bot Protection Security Vulnerabilities
WhoKnew Shield — Contact Obfuscation & Bot Protection Code Analysis
Output Escaping
WhoKnew Shield — Contact Obfuscation & Bot Protection Attack Surface
AJAX Handlers 2
Shortcodes 10
WordPress Hooks 27
Maintenance & Trust
WhoKnew Shield — Contact Obfuscation & Bot Protection Maintenance & Trust
Maintenance Signals
Community Trust
WhoKnew Shield — Contact Obfuscation & Bot Protection Alternatives
Email No Bot – Prevent bots from detecting emails
email-no-bot
Humans will see the email address on your page, but robots will not.
TG Email Protection
tg-email-protection
Protect email addresses from being harvested by spammers and spambots, obfuscating them. Your visitors can still see email addresses.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
contact-form-7-honeypot
Addons for Contact Form 7 — Honeypot, Database Entries, Redirection, Spam Protection, Webhooks, ACF integration for Contact Form 7, and more.
WhoKnew Shield — Contact Obfuscation & Bot Protection Developer Profile
1 plugin · 0 total installs
How We Detect WhoKnew Shield — Contact Obfuscation & Bot Protection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whoknew-shield/assets/js/whoknew-shield-public.js/wp-content/plugins/whoknew-shield/assets/css/whoknew-shield-public.css/wp-content/plugins/whoknew-shield/assets/js/whoknew-shield-public.jswhoknew-shield/assets/js/whoknew-shield-public.js?ver=whoknew-shield/assets/css/whoknew-shield-public.css?ver=HTML / DOM Fingerprints
whoknew-shield-obfuscateddata-whoknew-shield-emaildata-whoknew-shield-phonedata-whoknew-shield-addresswhoknewShield[encode][/encode][obfuscate_email][/obfuscate_email]