
BlossomThemes Email Newsletter Security & Risk Analysis
wordpress.org/plugins/blossomthemes-email-newsletterEasily add email subscription form to your website using shortcode and widget.
Is BlossomThemes Email Newsletter Safe to Use in 2026?
Generally Safe
Score 91/100BlossomThemes Email Newsletter has a strong security track record. Known vulnerabilities have been patched promptly.
The 'blossomthemes-email-newsletter' plugin version 2.2.10 presents a mixed security posture. On the positive side, the static analysis shows good practices in several areas. All identified entry points, including AJAX handlers and the shortcode, appear to have authorization checks in place, and there are no detected critical or high severity taint flows with unsanitized paths. Furthermore, all SQL queries utilize prepared statements, and a significant portion of output is properly escaped, mitigating common web vulnerabilities. The absence of file operations also reduces the attack surface.
However, there are areas that warrant attention. The plugin has a history of two medium severity CVEs, specifically SSRF and Missing Authorization, with the last vulnerability being very recent (2024-06-20). While currently unpatched CVEs are zero, this history suggests a recurring pattern of vulnerabilities that attackers could potentially exploit if new ones emerge. The presence of two external HTTP requests could be a vector for SSRF if not handled with extreme care, although the taint analysis did not reveal any unsanitized paths related to these. Finally, the bundled Guzzle library v1.1 is an older version, which may contain known vulnerabilities not yet addressed within this plugin.
In conclusion, while the plugin implements several robust security measures, its past vulnerability history, especially concerning SSRF and authorization, coupled with the outdated bundled library, indicates a need for vigilance. Users should ensure they are on the latest version for any patches and consider the potential risks associated with the plugin's previous security shortcomings.
Key Concerns
- Bundled outdated library Guzzle v1.1
- History of 2 medium CVEs (SSRF, Missing Authorization)
BlossomThemes Email Newsletter Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
BlossomThemes Email Newsletter <= 2.2.6 - Authenticated (Admin+) Server-Side Request Forgery
BlossomThemes Email Newsletter <= 2.2.4 - Missing Authorization
BlossomThemes Email Newsletter Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
BlossomThemes Email Newsletter Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 25
Maintenance & Trust
BlossomThemes Email Newsletter Maintenance & Trust
Maintenance Signals
Community Trust
BlossomThemes Email Newsletter Alternatives
MC4WP: Mailchimp for WordPress
mailchimp-for-wp
The #1 Mailchimp plugin for WordPress. Allows you to add a multitude of newsletter sign-up methods to your site.
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
fluent-crm
The easiest and fastest Email Marketing, Newsletter, Marketing Automation Plugin & CRM Solution for WordPress
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
email-subscribers
Add subscription forms on the website and send newsletters & automatically send post notification about new blog posts once it gets published.
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages
convertkit
Build your email subscriber lists, send email marketing newsletters, sell more products and build your membership site with Kit (formerly ConvertKit).
BlossomThemes Email Newsletter Developer Profile
79 plugins · 98K total installs
How We Detect BlossomThemes Email Newsletter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blossomthemes-email-newsletter/css/blossomthemes-email-newsletter-admin.css/wp-content/plugins/blossomthemes-email-newsletter/images/newsletter-icon/style.css/wp-content/plugins/blossomthemes-email-newsletter/js/blossomthemes-email-newsletter-admin.js/wp-content/plugins/blossomthemes-email-newsletter/js/bten-aweber.js/wp-content/plugins/blossomthemes-email-newsletter/js/bten-mailing-platform-lists.js/wp-content/plugins/blossomthemes-email-newsletter/js/blossomthemes-email-newsletter-admin.js/wp-content/plugins/blossomthemes-email-newsletter/js/bten-aweber.js/wp-content/plugins/blossomthemes-email-newsletter/js/bten-mailing-platform-lists.jsblossomthemes-email-newsletter/css/blossomthemes-email-newsletter-admin.css?ver=blossomthemes-email-newsletter/images/newsletter-icon/style.css?ver=blossomthemes-email-newsletter/js/blossomthemes-email-newsletter-admin.js?ver=bten-aweber?ver=bten-mailing-platform-lists?ver=HTML / DOM Fingerprints
blossomthemes-email-newsletter-admin-wrapdata-plugin-name="BlossomThemes Email Newsletter"data-plugin-uri="https://blossomthemes.com"bten_uploader[blossomthemes_email_newsletter_form][blossomthemes_email_newsletter_subscribe_form]