
Arigato Autoresponder and Newsletter Security & Risk Analysis
wordpress.org/plugins/bft-autoresponderThis plugin allows scheduling of automated autoresponder messages / drip marketing messages, instant newsletters, and managing a mailing list.
Is Arigato Autoresponder and Newsletter Safe to Use in 2026?
Use With Caution
Score 58/100Arigato Autoresponder and Newsletter has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The bft-autoresponder plugin exhibits a mixed security posture. While it demonstrates good practices in utilizing prepared statements for the vast majority of its SQL queries and includes a decent number of nonce and capability checks, several concerning signals emerge from the static analysis and vulnerability history. The presence of the `unserialize` function is a significant red flag, as it is a known vector for object injection vulnerabilities if not handled with extreme care and input validation. Furthermore, the taint analysis reveals several flows with unsanitized paths, including three identified as high severity. This, combined with the plugin's history of 18 known CVEs, including one critical unpatched vulnerability, points to a recurring pattern of security weaknesses that attackers have successfully exploited in the past. The types of common vulnerabilities (CSRF, XSS, Unrestricted Uploads, SQL Injection) further reinforce the need for heightened vigilance.
Key Concerns
- Unpatched critical vulnerability
- High severity taint flows detected
- Dangerous unserialize function present
- Unsanitized paths in taint analysis
- Output escaping only 57% proper
- Large number of past CVEs
Arigato Autoresponder and Newsletter Security Vulnerabilities
CVEs by Year
Severity Breakdown
18 total CVEs
Arigato Autoresponder and Newsletter <= 2.7.2.4 - Reflected Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.7.2.3 - Cross-Site Request Forgery
Arigato Autoresponder and Newsletter <= 2.7.2.2 - Cross-Site Request Forgery
Arigato Autoresponder and Newsletter <= 2.7.1 - Unauthenticated Stored Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.1.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.7 - Arbitrary File Upload
Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.5.1.8 - SQL Injection
Arigato Autoresponder and Newsletter <= 2.5.1.8 - Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.5.1.8 - Reflected Cross-Site Scripting
Arigato Autoresponder and Newsletter <= 2.5.1.8 - Cross-Site Scripting
Arigato Autoresponder and Newsletter Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Arigato Autoresponder and Newsletter Attack Surface
Shortcodes 5
WordPress Hooks 19
Scheduled Events 1
Maintenance & Trust
Arigato Autoresponder and Newsletter Maintenance & Trust
Maintenance Signals
Community Trust
Arigato Autoresponder and Newsletter Alternatives
Connect Contact Form 7 and AWeber
integrate-contact-form-7-and-aweber
Integrate AWeber mailing lists with Contact Form 7. Automatically add form subscribers to your AWeber lists.
Integrate Contact Form 7 and iContact
cf7-icontact-extension
Connect Contact Form 7 to iContact. Automatically add form submissions to your iContact mailing lists.
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
Lead Form Builder & Contact Form
lead-form-builder
Fast Drag & Drop Contact From Builder and Lead Generation Tool With Google One Tap Login. Supports Block Editor.
Drip for WordPress
email-marketing
Do you sell online? If so you need our new Drip for WooCommerce Plugin instead of this one. It includes your entire product catalog, order history int …
Arigato Autoresponder and Newsletter Developer Profile
9 plugins · 5K total installs
How We Detect Arigato Autoresponder and Newsletter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bft-autoresponder/front.css/wp-content/plugins/bft-autoresponder/css/admin.cssbft-autoresponder/front.css?ver=bft-autoresponder/css/admin.css?ver=HTML / DOM Fingerprints
bft-autoresponder[bft-num-subs][bft-unsubscribe][bft-newsletter-archive][bft-int-chk]