Newsletter Sign-Up for CleverReach Security & Risk Analysis

wordpress.org/plugins/cleverreach

Easily integrate a CleverReach Sign-Up form in your website. Supports widget, shortcode, comment integration and template function

2K active installs v2.3.5 PHP + WP 3.9+ Updated Sep 5, 2025
email-automationemail-marketing-toolintegrationmarketing-automationnewsletter
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Newsletter Sign-Up for CleverReach Safe to Use in 2026?

Generally Safe

Score 100/100

Newsletter Sign-Up for CleverReach has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The CleverReach plugin v2.3.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and a high percentage of properly escaped output. The absence of known CVEs and a clean vulnerability history are also strong indicators of a relatively secure plugin. However, significant concerns arise from the static analysis of its attack surface. With a total of 4 entry points, a concerning 3 are unprotected, specifically AJAX handlers lacking authentication checks. This absence of capability and nonce checks on these critical entry points presents a substantial risk of unauthorized actions being performed if these AJAX handlers are exploitable.

Key Concerns

  • Unprotected AJAX handlers
  • Missing nonce checks on AJAX
  • Missing capability checks
Vulnerabilities
None known

Newsletter Sign-Up for CleverReach Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Newsletter Sign-Up for CleverReach Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
32
185 escaped
Nonce Checks
0
Capability Checks
0
File Operations
5
External Requests
2
Bundled Libraries
0

Output Escaping

85% escaped217 total outputs
Attack Surface
3 unprotected

Newsletter Sign-Up for CleverReach Attack Surface

Entry Points4
Unprotected3

AJAX Handlers 3

authwp_ajax_cleverreach_preview_formincludes\class-cleverreach.php:118
authwp_ajax_cleverreach_submitincludes\Form\class-form.php:37
noprivwp_ajax_cleverreach_submitincludes\Form\class-form.php:38

Shortcodes 1

[cleverreach_signup] includes\Form\class-form.php:39
WordPress Hooks 11
actionadmin_menuincludes\class-cleverreach.php:115
actionadmin_enqueue_scriptsincludes\class-cleverreach.php:116
actionadmin_initincludes\class-cleverreach.php:117
actionwidgets_initincludes\class-cleverreach.php:119
actionplugins_loadedincludes\class-cleverreach.php:120
actionadmin_noticesincludes\class-cleverreach.php:196
actionadmin_noticesincludes\class-cleverreach.php:200
actioninitincludes\Form\class-form.php:35
actionwp_enqueue_scriptsincludes\Form\class-form.php:36
actioncomment_formincludes\NewsletterCheckbox\class-newsletter-checkbox.php:40
actioncomment_postincludes\NewsletterCheckbox\class-newsletter-checkbox.php:41
Maintenance & Trust

Newsletter Sign-Up for CleverReach Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 5, 2025
PHP min version
Downloads61K

Community Trust

Rating66/100
Number of ratings15
Active installs2K
Developer Profile

Newsletter Sign-Up for CleverReach Developer Profile

CleverReach®

3 plugins · 6K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
82 days
View full developer profile
Detection Fingerprints

How We Detect Newsletter Sign-Up for CleverReach

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cleverreach/resources/css/frontend.css/wp-content/plugins/cleverreach/resources/js/cleverreach-gutenberg.js/wp-content/plugins/cleverreach/resources/js/cleverreach-admin.js
Script Paths
/wp-content/plugins/cleverreach/resources/js/cleverreach-gutenberg.js/wp-content/plugins/cleverreach/resources/js/cleverreach-admin.js

HTML / DOM Fingerprints

CSS Classes
cleverreach-form-groupcleverreach-subscribe-formcleverreach-form-controlcleverreach-form-builder
HTML Comments
<!-- CleverReach Newsletter Signup Form --><!-- CleverReach Form Builder -->
Data Attributes
data-cleverreach-form-iddata-cr-input-type
JS Globals
cleverreachAdmincleverreachFrontend
REST Endpoints
/wp-json/cleverreach/v1/forms/wp-json/cleverreach/v1/settings
Shortcode Output
[cleverreach_signup_form][cleverreach_form_builder]
FAQ

Frequently Asked Questions about Newsletter Sign-Up for CleverReach