
AdRotater Email Ad Reports Security & Risk Analysis
wordpress.org/plugins/adrotate-email-add-onAdRotater Email Ad Reports allow you to send monthly ad reports to advertisers.
Is AdRotater Email Ad Reports Safe to Use in 2026?
Generally Safe
Score 85/100AdRotater Email Ad Reports has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "adrotate-email-add-on" v1.1.0 plugin exhibits a mixed security posture. On the surface, the attack surface appears to be zero, with no registered AJAX handlers, REST API routes, shortcodes, or cron events. This suggests a limited direct interaction surface. However, the code analysis reveals significant concerns, particularly regarding output escaping, where only 7% of outputs are properly escaped. This opens the door to potential cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered without sufficient sanitization.
The taint analysis is also a point of concern, showing one flow with an unsanitized path flagged as high severity. While the static analysis doesn't explicitly detail this flow, a high-severity unsanitized path strongly indicates a potential for code execution or privilege escalation if an attacker can inject malicious input. The plugin does implement nonce checks in three instances and uses prepared statements for 40% of its SQL queries, which are positive security practices. Nevertheless, the lack of capability checks is a notable weakness, as it implies that any user, regardless of their role, could potentially interact with and exploit functionality if an entry point is discovered.
The vulnerability history is exceptionally clean, with zero recorded CVEs. This could indicate either a well-developed and secure plugin or simply a lack of past scrutiny and discovery of potential vulnerabilities. In conclusion, while the plugin's attack surface appears minimal and it has a clean vulnerability history, the poor output escaping and the identified high-severity unsanitized taint flow represent substantial risks that require immediate attention. The absence of capability checks further compounds these potential weaknesses.
Key Concerns
- High severity unsanitized path in taint analysis
- Low percentage of properly escaped output
- No capability checks on entry points
- SQL queries not always using prepared statements
AdRotater Email Ad Reports Security Vulnerabilities
AdRotater Email Ad Reports Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
AdRotater Email Ad Reports Attack Surface
WordPress Hooks 5
Maintenance & Trust
AdRotater Email Ad Reports Maintenance & Trust
Maintenance Signals
Community Trust
AdRotater Email Ad Reports Alternatives
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation
sumome
Sumo is trusted by over 600,000 businesses — small and large — in growing their email lists, customer base, and revenue online.
Cart Lift – Abandoned Cart Recovery for WooCommerce and EDD
cart-lift
Track abandoned carts and send automated, customizable abandoned cart recovery emails. Get more leads, reduce cart abandonment, and increase revenue.
Recapture for Easy Digital Downloads
recapture-for-edd
Recapture is the easiest and most effective way to recover abandoned carts and do email marketing for your Easy Digital Downloads (EDD) store in WordP …
AdRotate Switch
adrotate-switch
Looking for a fresh start with AdRotate Banner Manager or AdRotate Professional but you don't want to have to re-do all your ads?
Sprout Clients – CRM and Lead Management
sprout-clients
Properly leveraging your contact lists isn’t sending out a single email to the entire list asking for work — instead you need to build business relati …
AdRotater Email Ad Reports Developer Profile
13 plugins · 110K total installs
How We Detect AdRotater Email Ad Reports
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/adrotate-email-add-on/css/adrotate-email-add-on.css/wp-content/plugins/adrotate-email-add-on/js/adrotate-email-add-on.js/wp-content/plugins/adrotate-email-add-on/js/adrotate-email-add-on.jsadrotate-email-add-on/css/adrotate-email-add-on.css?ver=adrotate-email-add-on/js/adrotate-email-add-on.js?ver=HTML / DOM Fingerprints
adrotate-email-add-onIf dependency requirements are not satisfied, self-deactivateDisplay an error message when the plugin deactivates itself.The class responsible for sending Emails to useradmin side of the site.+2 moredata-adrotate-email-add-on-noncedata-adrotate-email-advertiser-nonce