
WP User Notifier Security & Risk Analysis
wordpress.org/plugins/wp-user-notifierNotify a user about when he sent comment or form via Contact Form 7
Is WP User Notifier Safe to Use in 2026?
Generally Safe
Score 85/100WP User Notifier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-user-notifier v1.0 plugin exhibits a strong security posture in several key areas, notably the absence of known vulnerabilities and a complete lack of exploitable attack surface through common entry points like AJAX, REST API, and shortcodes. The code analysis also reveals a commitment to secure practices such as 100% prepared statement usage for SQL queries and the presence of a nonce check, which are positive indicators. However, a significant concern arises from the low rate of output escaping (38%). This suggests that user-supplied data, if it were to be processed and displayed, could be vulnerable to cross-site scripting (XSS) attacks, as the data might not be adequately sanitized before being rendered in the browser. While the current analysis shows no taint flows, this is likely due to the limited attack surface and the absence of complex data processing, rather than inherent sanitization practices. The lack of any recorded vulnerabilities in its history is a positive sign, but it does not negate the risks identified in the static analysis.
Key Concerns
- Low output escaping rate (38%)
WP User Notifier Security Vulnerabilities
WP User Notifier Release Timeline
WP User Notifier Code Analysis
Output Escaping
WP User Notifier Attack Surface
WordPress Hooks 4
Maintenance & Trust
WP User Notifier Maintenance & Trust
Maintenance Signals
Community Trust
WP User Notifier Alternatives
Notifier and IP Blocker
notifier-and-ip-blocker
Notify a user about when he sent comment or form via Contact Form 7 and automatically blocked spammer IP by notifier users.
Email id from comments
email-id-from-comments
This plugin extracts the email ids from the comments in your website. It can get email id from any comment which you have not deleted (approved,spam).
EmailKit – Email Customizer for WooCommerce & WP
emailkit
EmailKit is a powerful WordPress and WooCommerce email customizer tool, free for everyone! It allows users to customize and design templates that show …
YayMail – WooCommerce Email Customizer
yaymail
Customize WooCommerce email templates with an advanced drag-and-drop email builder. Works great with 80+ WooCommerce Email Customizer Addons.
Disqus Comment System
disqus-comment-system
Disqus is the web's most popular comment system. Use Disqus to increase engagement, retain readers, and grow your audience.
WP User Notifier Developer Profile
2 plugins · 20 total installs
How We Detect WP User Notifier
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
/*wp-user-notifier*/name="wp_user_notifier_enable"name="wp_user_notifier_comment_need_pending"name="wp_user_notifier_enabled_cf7"name="wp_user_notifier_subject"name="wp_user_notifier_message"name="wp_user_notifier"+3 more<input type="checkbox" name="wp_user_notifier_enable" value="1" <input type="checkbox" name="wp_user_notifier_comment_need_pending" value="1" <input type="checkbox" name="wp_user_notifier_enabled_cf7" value="1" <input type="text" name="wp_user_notifier_subject" class="large-text" value="