Email Encoder – Protect Email Addresses and Phone Numbers
by Online Optimisation · Security
Also makes 1 other plugin · 98K+ installs across the portfolio →
Protect email addresses and phone numbers on your site and hide them from spambots. Easy to use & flexible.
91 health vs 64 average across 997 Security plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Biggest win: Support resolution
To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.
Get the full rank-higher report →Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
66.0K
now · peak 270.6K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
24
releases in the last 12 months
1mo ago
latest release · v2.5.2
83
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 64% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “90K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-03-10 · 1,463 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ GuitarPix2mo ago
Exactly what I’d wanted out of it.
Read on wp.org ↗ - ★★★★★ RiccLazz3mo ago
best plugin for email encryption. would love to see an option to disable encryption based on css classes or IDs. would be an upgrade to this fantastic plugin.
Read on wp.org ↗ - ★★★★★ 720florian5mo ago
Good free plugin. I hope it will soon be able to automatically recognize phone numbers
Read on wp.org ↗ - ★★★★★ paulr256mo ago
I’m actually impressed that it’s still free.
Read on wp.org ↗ - ★★★★★ niveksa8mo ago
Excellent plugin and support. Highly recommended.
Read on wp.org ↗ - ★★★★★ fletchadam9mo ago
Encodes email addresses, phone numbers, ahrefs. Great!
Read on wp.org ↗ - ★★★★★ sankari10mo ago
Thanks for the quick fix and your friendly and attentive support!
Read on wp.org ↗ - ★★★★★ neotek912mo ago
Works great but needs an update. Thank you. Receiving this in the error log. Notice: Function _load_textdomain_just_in_time was called <strong>incorrectly</strong>. Translation loading for the <code>email-encoder-bundle</code> domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the <code>init</code> action or later. Please see <a href=”/”>Debugging in WordPress</a> for more information. (This message was added in version 6.7.0.) in /home/holistic/public_html/wp-includes/functions.php on line 6121 Happy to send a donation via PayPal. Cheers.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 2.5.2 Fix: On iPhone/iPad, an email link set to open in a new tab (or opened via “Open Link in New Tab”) could show a Safari “cannot run the script” error — email links are now real links that open the mail app cleanly in ever 2.5.2
- — Version 2.5.1 Fix: On large pages, a plain email inside another plugin’s inline script data (for example the Helpie FAQ list) could be encoded there and break that script, spilling raw content into the space below the footer — inline 2.5.1
- — Version 2.5.0 Feature: Redesigned settings page — branded header with logo and version, modern layout, friendlier form controls Feature: Reorganised settings into clearer tabs, including a dedicated Exclusions tab and a tidied-up Tool 2.5.0
- — Version 2.4.8 Fix: Emails inside dropdown options now display correctly in Firefox (and consistently across all browsers) Fix: Rich-text and styled markup inside mailto links (Divi 4 Text modules, Divi 5 Link blocks, etc.) is now pres 2.4.8
- — Version 2.4.7 Security: Escaped data-enc-email attribute output to close XSS bypass reported by WPScan (CVE-2026-2840 follow-up) 2.4.7
- — Version 2.4.6 Fix: Resolved _load_textdomain_just_in_time warning on WordPress 6.7+ Feature: Added “Copy Support Info” button to admin sidebar for easier support diagnostics Tweak: Improved settings loading performance with two-phase 2.4.6
Known vulnerabilities
via Wordfence Intelligence10 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-06-11 CVE-2026-5776 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.4.7 Patched in 2.4.7
- 2026-04-21 CVE-2024-7083 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.3.4 Patched in 2.3.4
- 2026-04-15 CVE-2026-2840 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.4.4 Patched in 2.4.5
- 2024-07-08 CVE-2024-4483 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.1 Patched in 2.2.2
- 2024-02-13 CVE-2024-1282 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.0 Patched in 2.2.1
- 2024-01-09 CVE-2023-7070 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.1.9 Patched in 2.1.10
- Medium · 6.4 Email Encoder Bundle <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode ↗2023-11-15 CVE-2023-47821 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.1.8 Patched in 2.1.9
- Medium · 6.4 Email Encoder <= 2.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode ↗2023-08-29 CVE-2023-4599 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.1.8 Patched in 2.1.9
- 2021-08-02 CVE-2021-24599 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.1.1 Patched in 2.1.2
- Medium · 6.1 Email Encoder < 1.4.2 - Cross-Site Scripting ↗2015-08-10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.4.2 Patched in 1.4.2
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0.1
Languages
via translate.wordpress.orgTranslated into 46 languages, 5 at 90% or more
Plus 22 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2024-02-29 80K+ → 90K+ up after 407 days in tier
- 2023-01-18 70K+ → 80K+ up after 3 days in tier
- 2023-01-15 80K+ → 70K+ down after 1 days in tier
- 2023-01-14 70K+ → 80K+ up after 1 days in tier
- 2023-01-13 80K+ → 70K+ down after 1 days in tier
- 2023-01-12 70K+ → 80K+ up after 6 days in tier
- 2023-01-06 80K+ → 70K+ down after 2 days in tier
- 2023-01-04 70K+ → 80K+ up after 3 days in tier
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
- W wL Email Encrypter 90+ installs · 3.6★ · 3 shared tags D
-
Email Address Obfuscation 2K+ installs · 4.2★ · 2 shared tags A -
PDF Password Protect 200+ installs · 4.0★ · 2 shared tags B -
Akismet Anti-spam: Spam Protection 5M+ installs · 4.7★ · 1 shared tag A -
Antispam Bee 700K+ installs · 4.8★ · 1 shared tag A -
WP Armour – Honeypot Anti Spam 400K+ installs · 5.0★ · 1 shared tag B
Embed this report card
Drop a live Pulse card for Email Encoder – Protect Email Addresses and Phone Numbers into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/email-encoder-bundle" width="480" height="300" style="border:0" loading="lazy" title="Email Encoder – Protect Email Addresses and Phone Numbers — Plugin Pulse"></iframe> Email Encoder – Protect Email Addresses and Phone Numbers: 90K+ active installs, 4.9★ (93 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/email-encoder-bundle