
WhoKnew Shield — Email, Phone & Address Security Security & Risk Analysis
wordpress.org/plugins/whoknew-shieldSecurity plugin blocking spam bots from harvesting email addresses, phone numbers & addresses. Dual-layer anti-spam protection with auto-detection.
Is WhoKnew Shield — Email, Phone & Address Security Safe to Use in 2026?
Generally Safe
Score 100/100WhoKnew Shield — Email, Phone & Address Security has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The whoknew-shield v2.0.1 plugin exhibits a very strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, raw SQL queries, and external HTTP requests are significant strengths. Furthermore, the high percentage of properly escaped output (99%) and the presence of nonce and capability checks on all identified entry points suggest a well-hardened codebase. The plugin also has no recorded vulnerability history, indicating a sustained commitment to security or a lack of past exploits, both positive indicators.
While the static analysis shows an attack surface of 12 entry points, all are protected by authentication or permission checks. The taint analysis revealing zero flows with unsanitized paths is particularly encouraging, as this often indicates potential for critical vulnerabilities like RCE or SQL injection. The only area that could be marginally improved is ensuring 100% output escaping, though 99% is generally considered very good.
In conclusion, whoknew-shield v2.0.1 appears to be a secure plugin. Its developers have implemented robust security practices, and there is no evidence of past vulnerabilities or concerning code patterns in the static analysis. The plugin's security posture is excellent, with minimal to no apparent risks.
WhoKnew Shield — Email, Phone & Address Security Security Vulnerabilities
WhoKnew Shield — Email, Phone & Address Security Release Timeline
WhoKnew Shield — Email, Phone & Address Security Code Analysis
Output Escaping
WhoKnew Shield — Email, Phone & Address Security Attack Surface
AJAX Handlers 2
Shortcodes 10
WordPress Hooks 27
Maintenance & Trust
WhoKnew Shield — Email, Phone & Address Security Maintenance & Trust
Maintenance Signals
Community Trust
WhoKnew Shield — Email, Phone & Address Security Alternatives
Stop Spammers Classic
stop-spammer-registrations-plugin
A simplified, restored, and preserved version of the original Stop Spammers plugin.
Dam Spam
dam-spam
Comprehensive spam protection for WordPress registration, login, comments, and contact forms.
Universal Honey Pot
universal-honey-pot
Universal Honey Pot is a powerful and user-friendly WordPress plugin that provides a plug-and-play solution for protecting your forms against unwanted …
Mail Cloak
mail-cloak
Advanced email protection with intelligent bot detection and automated security monitoring for WordPress websites.
SpamShieldX
automatic-break-iframes
SpamShieldX is the ultimate solution for protecting your WordPress website from spam and iframe abuse. Our plugin blocks malicious iframes and prevent …
WhoKnew Shield — Email, Phone & Address Security Developer Profile
2 plugins · 0 total installs
How We Detect WhoKnew Shield — Email, Phone & Address Security
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whoknew-shield/assets/js/whoknew-shield-public.js/wp-content/plugins/whoknew-shield/assets/css/whoknew-shield-public.css/wp-content/plugins/whoknew-shield/assets/js/whoknew-shield-public.jswhoknew-shield/assets/js/whoknew-shield-public.js?ver=whoknew-shield/assets/css/whoknew-shield-public.css?ver=HTML / DOM Fingerprints
whoknew-shield-obfuscateddata-whoknew-shield-emaildata-whoknew-shield-phonedata-whoknew-shield-addresswhoknewShield[encode][/encode][obfuscate_email][/obfuscate_email]