
Subscribe Button by AddToAny Security & Risk Analysis
wordpress.org/plugins/add-to-any-subscribeHelp visitors subscribe to your blog using email or any feed reader, such as Feedly, The Old Reader, Yahoo!, AOL, and many more feed services.
Is Subscribe Button by AddToAny Safe to Use in 2026?
Generally Safe
Score 85/100Subscribe Button by AddToAny has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "add-to-any-subscribe" plugin version 9.10.0 exhibits a mixed security posture. On the positive side, the plugin reports zero AJAX handlers, REST API routes, shortcodes, or cron events, indicating a potentially small attack surface and no immediately obvious direct entry points for attackers. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, which are good security practices. However, there are significant concerns arising from the static analysis. The presence of a dangerous `create_function` is a red flag, as this function can be exploited for code execution if not handled with extreme care. More critically, 100% of output is not properly escaped, posing a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the vulnerability history is clean, this does not negate the risks identified in the code analysis, especially the unescaped output. The single taint flow with an unsanitized path, although not classified as critical or high, warrants attention given the overall lack of output escaping. In conclusion, while the plugin appears to have a limited direct attack surface and good database practices, the lack of output escaping and the use of `create_function` represent serious potential security weaknesses that need to be addressed.
Key Concerns
- Unescaped output
- Dangerous function used (create_function)
- Flow with unsanitized paths
Subscribe Button by AddToAny Security Vulnerabilities
Subscribe Button by AddToAny Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Subscribe Button by AddToAny Attack Surface
WordPress Hooks 5
Maintenance & Trust
Subscribe Button by AddToAny Maintenance & Trust
Maintenance Signals
Community Trust
Subscribe Button by AddToAny Alternatives
Podlove Subscribe button
podlove-subscribe-button
Podlove Subscribe button allows your users to easily select a podcast feed and pass it along to their favorite podcast app.
Simple Statistics for Feeds
simple-feed-stats
Tracks your feeds and displays your feed count via shortcode.
Subscribe Here Widget
subscribe-here-widget
Subscribe Here displays a visible plugin widget in the sidebar with Subscribe by Rss & Subscribe by Email(through Feedburner) options.
RSS Links Manager
rss-links-manager
Manage and customise your RSS feed links.
Cartograf Featured-image in Feed
cartograf-featured-image-in-feed
Includes the featured image of a post at the beginning of the item's content in the WordPress generated feeds. With this plugin, you no longer ne …
Subscribe Button by AddToAny Developer Profile
2 plugins · 301K total installs
How We Detect Subscribe Button by AddToAny
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-to-any-subscribe/languageshttps://static.addtoany.com/menu/page.jsHTML / DOM Fingerprints
a2a_followa2a_ddaddtoany_subscribedata-a2a-urla2a_configa2a_localize