
WP Mailto Links – Protect Email Addresses Security & Risk Analysis
wordpress.org/plugins/wp-mailto-linksProtect & encode email addresses safely from spambots & spamming. Easy to use - encodes emails out-of-the-box.
Is WP Mailto Links – Protect Email Addresses Safe to Use in 2026?
Use With Caution
Score 62/100WP Mailto Links – Protect Email Addresses has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-mailto-links plugin, version 3.1.4, presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and includes nonce and capability checks for its entry points. The attack surface appears limited with no unprotected AJAX handlers or REST API routes.
However, several concerns warrant attention. The low percentage of properly escaped output (18%) is a significant red flag, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, a pattern supported by its vulnerability history. While the static analysis found no immediate critical or high severity issues, the taint analysis reveals flows with unsanitized paths, suggesting potential weaknesses that could be exploited, especially in conjunction with improper output escaping.
The plugin has a history of two medium severity CVEs, with one currently unpatched, both related to XSS. This history, coupled with the low output escaping percentage, strongly suggests a recurring problem with handling user-supplied data securely, potentially leading to further exploitable vulnerabilities.
Key Concerns
- Unpatched CVE
- Low output escaping percentage (18%)
- Taint flows with unsanitized paths
- History of XSS vulnerabilities
WP Mailto Links – Protect Email Addresses Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Mailto Links <= 3.1.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
WP Mailto Links – Protect Email Addresses <= 3.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
WP Mailto Links – Protect Email Addresses Code Analysis
Output Escaping
Data Flow Analysis
WP Mailto Links – Protect Email Addresses Attack Surface
Shortcodes 2
WordPress Hooks 15
Maintenance & Trust
WP Mailto Links – Protect Email Addresses Maintenance & Trust
Maintenance Signals
Community Trust
WP Mailto Links – Protect Email Addresses Alternatives
wk-email-antibot
wk-email-antibot
Simply enables WordPress shortcode for easily letting you camouflage an email address, hiding it from crawling spiders and bots.
CryptX
cryptx
No more SPAM by spiders scanning your site for email addresses!
User Verification by PickPlugins
user-verification
Email verification for user registration to protect spam.
Disable Auto Update Emails and Block Updates for Plugins, WP Core, and Themes
disable-email-notification-for-auto-updates
This plugin disables email notifications for auto-updates and blocks updates for specific plugins, hide plugins, WordPress core, and themes.
Customer Email Verification for WooCommerce
customer-email-verification-for-woocommerce
Secure WooCommerce registrations with OTP-based email verification, reducing spam and ensuring only valid email addresses are used.
WP Mailto Links – Protect Email Addresses Developer Profile
2 plugins · 99K total installs
How We Detect WP Mailto Links – Protect Email Addresses
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-mailto-links/core/includes/assets/js/custom-admin.js/wp-content/plugins/wp-mailto-links/core/includes/assets/css/style-admin.css/wp-content/plugins/wp-mailto-links/core/includes/assets/js/custom-admin.jswp-mailto-links/core/includes/assets/js/custom-admin.js?ver=wp-mailto-links/core/includes/assets/css/style-admin.css?ver=