
WP Email Invisibliser Security & Risk Analysis
wordpress.org/plugins/wp-email-invisibliserA simple plugin to hide emails from spambots. Simply use the shortcode [hide_email myemail@mydomain.com] to hide myemail@mydomain.
Is WP Email Invisibliser Safe to Use in 2026?
Generally Safe
Score 85/100WP Email Invisibliser has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wp-email-invisibliser' v0.1.2 plugin exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The code successfully employs prepared statements for all SQL queries, demonstrates proper output escaping for all outputs, and has no recorded file operations or external HTTP requests. Crucially, there are no identified critical or high-severity taint flows, indicating a lack of easily exploitable data manipulation vulnerabilities within the analyzed code.
However, there are several areas that warrant attention. The absence of any nonce checks and capability checks is a significant concern. While the current attack surface is small and appears to have no unprotected entry points in this specific analysis, these checks are fundamental security mechanisms that prevent a wide range of attacks, including Cross-Site Request Forgery (CSRF) and unauthorized access. The presence of a shortcode as an entry point without any associated authentication or permission checks, even if it's the only entry point, represents a potential vulnerability if the shortcode's functionality is sensitive or can be manipulated.
The vulnerability history being completely clear is a positive sign, suggesting the developers have a good track record or that the plugin has not been subjected to extensive security scrutiny. Nevertheless, the lack of protective measures like nonce and capability checks means that even a simple, seemingly harmless shortcode could become a vector for attacks if its functionality is not robustly secured.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
- Shortcode without Auth Checks
WP Email Invisibliser Security Vulnerabilities
WP Email Invisibliser Code Analysis
WP Email Invisibliser Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
WP Email Invisibliser Maintenance & Trust
Maintenance Signals
Community Trust
WP Email Invisibliser Alternatives
CryptX
cryptx
No more SPAM by spiders scanning your site for email addresses!
WP Mailto Links – Protect Email Addresses
wp-mailto-links
Protect & encode email addresses safely from spambots & spamming. Easy to use - encodes emails out-of-the-box.
HumansNotBots – Easy, Accessible Email Cloaker
humansnotbots
"email AT address DOT com" (without quotes) is converted to a clickable version of email@address.com if JavaScript is enabled.
WP-AntiSpambot
wp-antispambot
Adds a shortcode which converts email addresses to HTML entities to block spambots.
EmailScrambler
emailscrambler
A lightweight plugin to protect email addresses from email-harvesting
WP Email Invisibliser Developer Profile
4 plugins · 130 total installs
How We Detect WP Email Invisibliser
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-email-invisibliser/js/hide_email.js/wp-content/plugins/wp-email-invisibliser/js/hide_email.jswp-email-invisibliser/js/hide_email.js?ver=HTML / DOM Fingerprints
wp_hide_email<span class='wp_hide_email