
Benchmark Email Lite Security & Risk Analysis
wordpress.org/plugins/benchmark-email-liteYour Wordpress Site and Email Marketing all in one place!
Is Benchmark Email Lite Safe to Use in 2026?
Generally Safe
Score 99/100Benchmark Email Lite has a strong security track record. Known vulnerabilities have been patched promptly.
The "benchmark-email-lite" v4.3.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding SQL query security, exclusively using prepared statements and having no identified critical or high severity vulnerabilities in its static analysis. The absence of dangerous functions, file operations, and bundled libraries further contributes to a generally robust foundation. However, there are notable areas of concern. The presence of a REST API route without permission callbacks creates a potential attack vector that is not adequately protected. While the taint analysis did not reveal any critical or high severity flows, the unprotected REST API endpoint represents an immediate risk of unauthorized access or manipulation if not properly secured by the user or through future plugin updates. The vulnerability history, while currently showing no unpatched issues, includes a past medium severity vulnerability (CSRF), suggesting that the plugin has had exploitable weaknesses in the past. This, coupled with the unprotected REST API endpoint, indicates a need for continued vigilance and prompt updates.
Key Concerns
- REST API route without permission callbacks
- Medium severity vulnerability in history
- Untrusted output (70% escaped)
Benchmark Email Lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Benchmark Email Lite <= 4.1 - Cross-Site Request Forgery via page_settings()
Benchmark Email Lite Code Analysis
Output Escaping
Data Flow Analysis
Benchmark Email Lite Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 16
Scheduled Events 1
Maintenance & Trust
Benchmark Email Lite Maintenance & Trust
Maintenance Signals
Community Trust
Benchmark Email Lite Alternatives
Drip for WordPress
email-marketing
Do you sell online? If so you need our new Drip for WooCommerce Plugin instead of this one. It includes your entire product catalog, order history int …
Campaign Monitor for WordPress
forms-for-campaign-monitor
Make it easy for customers to subscribe to your Campaign Monitor mailing lists using any of the 5 elegant sign-up forms.
Mailster Gravity Forms
mailster-gravity-forms
Integrates Mailster Newsletter Plugin with Gravity Forms to subscribe users with a Gravity Form.
Get a Newsletter
getanewsletter
Turn visitors into subscribers. Eliminate manual entry of subscribers with signup forms that sync directly with your Get a Newsletter account.
Connect Contact Form 7 and AWeber
integrate-contact-form-7-and-aweber
Integrate AWeber mailing lists with Contact Form 7. Automatically add form subscribers to your AWeber lists.
Benchmark Email Lite Developer Profile
1 plugin · 1K total installs
How We Detect Benchmark Email Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/benchmark-email-lite/css/admin.css/wp-content/plugins/benchmark-email-lite/js/admin.js/wp-content/plugins/benchmark-email-lite/js/frontend.jshttps://prod.benchmarkemail.com/tracker.bundle.jsbenchmark-email-lite/css/admin.css?ver=benchmark-email-lite/js/admin.js?ver=benchmark-email-lite/js/frontend.js?ver=HTML / DOM Fingerprints
benchmark-email-signupwindow.apScriptInserted_paq/wp-json/wpbme/v1/signupforms<div class="benchmark-email-signup">