WP Simple Notify Security & Risk Analysis

wordpress.org/plugins/wp-simple-notify

Easiest WP Plugin to manage email notifications for common events such as user's post comments.

10 active installs v1.2 PHP 7.0+ WP 4.6+ Updated Apr 16, 2020
commentsemailnotifications
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Simple Notify Safe to Use in 2026?

Generally Safe

Score 85/100

WP Simple Notify has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the wp-simple-notify plugin v1.2 exhibits a strong security posture with no identified vulnerabilities in its current version. The code analysis reveals an absence of dangerous functions, SQL injection risks through prepared statements, and proper output escaping. Crucially, there are no identified attack vectors through AJAX, REST API, shortcodes, or cron events, and no external requests or file operations that could be exploited. This indicates a diligent approach to secure coding practices.

The vulnerability history further supports this positive assessment, with no recorded CVEs, past or present. The absence of common vulnerability types suggests a mature and well-maintained codebase that has not historically presented significant security weaknesses. The lack of taint flows with unsanitized paths further reinforces the conclusion that the plugin is not susceptible to common data-related vulnerabilities.

In conclusion, wp-simple-notify v1.2 appears to be a secure plugin. Its strengths lie in the complete lack of exploitable entry points, secure data handling through prepared statements and proper escaping, and a clean vulnerability history. While the lack of nonce and capability checks on the identified entry points is technically present, given that there are zero entry points to begin with, this does not represent a practical security risk in this specific version. The plugin demonstrates excellent security practices.

Vulnerabilities
None known

WP Simple Notify Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Simple Notify Release Timeline

v1.2Current
v1.1
Code Analysis
Analyzed Mar 17, 2026

WP Simple Notify Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Attack Surface

WP Simple Notify Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_enqueue_scriptssrc\Bootstrap.php:42
actionadmin_menusrc\Bootstrap.php:44
actionwp-simple-notify-settings-endsrc\Bootstrap.php:46
actioncomment_postsrc\Controller.php:35
actioncomment_postsrc\Controller.php:38
actionrest_api_initsrc\Settings.php:54
Maintenance & Trust

WP Simple Notify Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedApr 16, 2020
PHP min version7.0
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

WP Simple Notify Developer Profile

Chris Baltazar

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Simple Notify

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-simple-notify/src/js/main.js/wp-content/plugins/wp-simple-notify/src/assets/bootstrap-4.4.1.min.css/wp-content/plugins/wp-simple-notify/src/assets/bootstrap-4.4.1.min.js/wp-content/plugins/wp-simple-notify/src/assets/font-awesome-4.7.0.min.css/wp-content/plugins/wp-simple-notify/src/assets/vue-dev.js/wp-content/plugins/wp-simple-notify/src/assets/vue@2.6.11.js/wp-content/plugins/wp-simple-notify/src/assets/vue-resource@1.5.1.js
Script Paths
/wp-content/plugins/wp-simple-notify/src/js/main.js

HTML / DOM Fingerprints

JS Globals
wsnConfigwsnActionswsnEndpointwsnIsReady
REST Endpoints
/wp-json/wp-simple-notify/save/wp-json/wp-simple-notify/action/wp-json/wp-simple-notify/test
FAQ

Frequently Asked Questions about WP Simple Notify