Email Notifications for Updates Security & Risk Analysis

wordpress.org/plugins/wp-update-mail-notification

Automatic E-mail notifications for outdated plugins. Select multiple recipients and use our beautiful E-mail layout with plugin thumbnails.

100 active installs v1.2.0 PHP 7.0+ WP 4.7+ Updated Apr 2, 2025
e-mailnew-updatesnoticeplugin-updatesystem
90
A · Safe
CVEs total1
Unpatched0
Last CVEApr 4, 2025
Download
Safety Verdict

Is Email Notifications for Updates Safe to Use in 2026?

Generally Safe

Score 90/100

Email Notifications for Updates has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 4, 2025Updated 1yr ago
Risk Assessment

The wp-update-mail-notification plugin v1.2.0 exhibits a concerning security posture primarily due to a significant lack of authorization checks and a history of past vulnerabilities. While the static analysis indicates no dangerous functions or SQL injection risks due to prepared statements, the presence of unprotected AJAX handlers presents a direct entry point for potential attackers. The complete absence of output escaping on 15 identified outputs is a critical weakness, meaning that any data processed by these outputs could be rendered directly in the browser, opening the door for cross-site scripting (XSS) attacks. The plugin also lacks nonce and capability checks, further exacerbating the risk associated with its unprotected entry points. The vulnerability history, including a past high-severity vulnerability related to missing authorization, suggests a pattern of insecure coding practices. Although there are no currently unpatched vulnerabilities, the past incidents and the current code analysis highlight a need for significant security improvements to mitigate the risks of unauthorized access and data manipulation.

Key Concerns

  • 1 unprotected AJAX handler
  • 0% of outputs properly escaped
  • 0 nonce checks
  • 0 capability checks
  • 1 past high severity vulnerability
Vulnerabilities
1

Email Notifications for Updates Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-2933high · 8.8Missing Authorization

Email Notifications for Updates <= 1.1.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update

Apr 4, 2025 Patched in 1.2.0 (18d)
Code Analysis
Analyzed Mar 16, 2026

Email Notifications for Updates Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped15 total outputs
Attack Surface
1 unprotected

Email Notifications for Updates Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_awun-send-test-emailplugin.php:119
WordPress Hooks 8
actionadmin_enqueue_scriptsenqueue.php:11
actionawun-scheduledmailing.php:56
filterawun-mail-subjectmailing.php:147
filterawun-mail-contentmailing.php:148
actionadmin_initoptions-page\options-page.php:18
actionadmin_menuoptions-page\options-page.php:21
filtercron_schedulesplugin.php:96
actionplugins_loadedplugin.php:125

Scheduled Events 5

awun-scheduled
awun-scheduled
awun-scheduled
awun-scheduled
awun-scheduled
Maintenance & Trust

Email Notifications for Updates Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedApr 2, 2025
PHP min version7.0
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Email Notifications for Updates Developer Profile

AWEOS GmbH

10 plugins · 6K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
13 days
View full developer profile
Detection Fingerprints

How We Detect Email Notifications for Updates

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-update-mail-notification/options-page/options-page.js
Version Parameters
wp-update-mail-notification/options-page/options-page.js?ver=

HTML / DOM Fingerprints

JS Globals
awun-options-page
FAQ

Frequently Asked Questions about Email Notifications for Updates