Bancomail Email Lists Integration Security & Risk Analysis

wordpress.org/plugins/bancomail-email-lists-integration

A free, powerful plugin that empowers you to resell online the Bancomail database, quickly and easily.

10 active installs v1.1.4 PHP + WP 4.0+ Updated Sep 10, 2018
busines-email-listse-commerceecommerceemail-listsemail-marketing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bancomail Email Lists Integration Safe to Use in 2026?

Generally Safe

Score 85/100

Bancomail Email Lists Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'bancomail-email-lists-integration' plugin v1.1.4 exhibits a concerning security posture primarily due to significant weaknesses in its code handling of data and lack of essential security checks. While the plugin has no recorded vulnerability history, this should not be taken as an indicator of robust security, as the static analysis reveals several red flags. The absence of any nonce checks or capability checks on potentially sensitive operations is a major concern. Furthermore, a significant portion of the plugin's output is not properly escaped, creating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis highlighting two high-severity flows with unsanitized paths, along with all analyzed flows having unsanitized paths, indicates a high probability of code injection or other data manipulation vulnerabilities. The fact that none of the SQL queries utilize prepared statements is a critical omission, exposing the plugin to SQL injection attacks. Despite the absence of documented CVEs and a zero attack surface in terms of traditional WordPress entry points (AJAX, REST API, shortcodes), the underlying code quality and data handling practices present a significant risk.

Key Concerns

  • High severity taint flows with unsanitized paths
  • All analyzed flows with unsanitized paths
  • 0% SQL queries using prepared statements
  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Bancomail Email Lists Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Bancomail Email Lists Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
0 prepared
Unescaped Output
316
154 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared5 total queries

Output Escaping

33% escaped470 total outputs
Data Flows
7 unsanitized

Data Flow Analysis

7 flows7 with unsanitized paths
BMWS_elenchi_email (bancomail-email-lists-integration.php:734)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Bancomail Email Lists Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_enqueue_scriptsbancomail-email-lists-integration.php:51
actionadmin_enqueue_scriptsbancomail-email-lists-integration.php:52
actionadmin_menubancomail-email-lists-integration.php:53
actionwpbancomail-email-lists-integration.php:54
actionwp_enqueue_scriptsbancomail-email-lists-integration.php:55
actionwp_enqueue_scriptsbancomail-email-lists-integration.php:56
actionafter_setup_themebancomail-email-lists-integration.php:58
Maintenance & Trust

Bancomail Email Lists Integration Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 10, 2018
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Bancomail Email Lists Integration Developer Profile

Bancomail - Neosoft

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Bancomail Email Lists Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bancomail-email-lists-integration/css/bmws-style.css/wp-content/plugins/bancomail-email-lists-integration/css/order-history.css/wp-content/plugins/bancomail-email-lists-integration/css/styles.css/wp-content/plugins/bancomail-email-lists-integration/js/bmws-script.js/wp-content/plugins/bancomail-email-lists-integration/js/order-history.js
Script Paths
/wp-content/plugins/bancomail-email-lists-integration/js/bmws-script.js/wp-content/plugins/bancomail-email-lists-integration/js/order-history.js
Version Parameters
/wp-content/plugins/bancomail-email-lists-integration/css/bmws-style.css?ver=/wp-content/plugins/bancomail-email-lists-integration/css/order-history.css?ver=/wp-content/plugins/bancomail-email-lists-integration/css/styles.css?ver=/wp-content/plugins/bancomail-email-lists-integration/js/bmws-script.js?ver=/wp-content/plugins/bancomail-email-lists-integration/js/order-history.js?ver=

HTML / DOM Fingerprints

CSS Classes
bmws_order_history_wrapbmws_cart_details_wrap
HTML Comments
<!-- BEGIN: BANCOMAIL EMAIL LISTS INTEGRATION --><!-- END: BANCOMAIL EMAIL LISTS INTEGRATION -->
Data Attributes
data-bmws-order-iddata-bmws-product-id
JS Globals
bmws_ajax_object
FAQ

Frequently Asked Questions about Bancomail Email Lists Integration