ActiveCampaign Newsletter Subscription Security & Risk Analysis

wordpress.org/plugins/activecampaign-newsletter-subscription

This is Newsletter Subscription Plugin, Which is used to add users to Selected ActiveCampaign List.

10 active installs v1.0.2 PHP 5.6+ WP 4.0+ Updated Jun 15, 2022
active-campaignactivecampaignnewsletternewsletter-subscription
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ActiveCampaign Newsletter Subscription Safe to Use in 2026?

Generally Safe

Score 85/100

ActiveCampaign Newsletter Subscription has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "activecampaign-newsletter-subscription" plugin version 1.0.2 exhibits a generally strong security posture based on the provided static analysis. The plugin has no known vulnerabilities, which is a significant positive indicator. Furthermore, the code signals reveal good development practices, including 100% of SQL queries using prepared statements and a high percentage (80%) of output escaping. The absence of dangerous functions, file operations, and critical/high severity taint flows further strengthens this assessment.

However, there are a few areas that warrant attention. The lack of capability checks (0) is a notable concern, as it suggests that certain actions within the plugin might not be properly restricted to authorized users. While there's only one nonce check, and the attack surface is reported as zero unprotected entry points, the absence of explicit capability checks could, in certain contexts, leave room for privilege escalation if combined with other factors. The presence of external HTTP requests (2) should be monitored for secure implementation, though they are not flagged as inherently problematic in this analysis.

In conclusion, the plugin is relatively secure with no known vulnerabilities and good internal coding practices for SQL and output handling. The primary area for improvement is the implementation of robust capability checks to ensure all actions are properly authorized. The low overall risk is commendable, but the absence of capability checks represents a potential weakness that should be addressed to achieve a more comprehensive security assurance.

Key Concerns

  • Lack of capability checks
  • External HTTP requests present
  • Lower output escaping percentage (80%)
Vulnerabilities
None known

ActiveCampaign Newsletter Subscription Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ActiveCampaign Newsletter Subscription Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
12 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

80% escaped15 total outputs
Attack Surface

ActiveCampaign Newsletter Subscription Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedactivecampaign-newsletter-subscription.php:62
actionadmin_menuapp\admin\class-activecampaign-newsletter-subscription-admin.php:29
actionadmin_initapp\admin\class-activecampaign-newsletter-subscription-admin.php:32
actionadmin_noticesapp\admin\class-activecampaign-newsletter-subscription-admin.php:160
actionregister_formapp\main\class-activecampaign-newsletter-subscription.php:30
actionuser_registerapp\main\class-activecampaign-newsletter-subscription.php:33
Maintenance & Trust

ActiveCampaign Newsletter Subscription Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 15, 2022
PHP min version5.6
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ActiveCampaign Newsletter Subscription Developer Profile

Bili Plugins

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ActiveCampaign Newsletter Subscription

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/activecampaign-newsletter-subscription/assets/css/acns-style.css/wp-content/plugins/activecampaign-newsletter-subscription/assets/js/acns-script.js

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about ActiveCampaign Newsletter Subscription