
CleverReach® WP Security & Risk Analysis
wordpress.org/plugins/cleverreach-wpConnect your WordPress account with our easy-to-use email software and increase the success of your website or blog with newsletter marketing!
Is CleverReach® WP Safe to Use in 2026?
Generally Safe
Score 94/100CleverReach® WP has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The cleverreach-wp plugin v1.5.23 exhibits a mixed security posture. While it demonstrates good practices in output escaping and SQL query preparedness, with a high percentage of outputs being properly escaped and a significant portion of SQL queries using prepared statements, there are notable areas of concern. The presence of the `unserialize` function is a significant risk signal, as it can lead to object injection vulnerabilities if not handled with extreme care and strict validation of the serialized data. The complete absence of nonce checks across all entry points, especially with a limited but present attack surface, is a major weakness. Furthermore, the plugin has a history of known high-severity vulnerabilities, specifically SQL injection, indicating potential for recurring issues in how external data is handled. While there are currently no unpatched CVEs, the historical pattern of high-severity SQL injection vulnerabilities is a strong indicator of past weaknesses that could resurface or be exploited in similar ways.
Key Concerns
- Presence of 'unserialize' function
- Zero nonce checks
- History of 2 high severity CVEs
- SQL Injection vulnerability type history
CleverReach® WP Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
CleverReach® WP <= 1.5.21 - Unauthenticated SQL Injection
CleverReach WP <= 1.5.20 - Unauthenticated SQL Injection via title Parameter
CleverReach® WP Release Timeline
CleverReach® WP Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
CleverReach® WP Attack Surface
Shortcodes 1
WordPress Hooks 38
Maintenance & Trust
CleverReach® WP Maintenance & Trust
Maintenance Signals
Community Trust
CleverReach® WP Alternatives
Newsletter Sign-Up for CleverReach
cleverreach
Easily integrate a CleverReach Sign-Up form in your website. Supports widget, shortcode, comment integration and template function
Official CleverReach® Plugin for WooCommerce
cleverreach-wc
Connect your WooCommerce store to our email software and say hello to successful and simple newsletter marketing – just like Spotify, Bugatti & DHL!
Boldermail – Email Marketing and Newsletters for WordPress
boldermail
Send marketing emails reliably from your WordPress dashboard with Boldermail, a powerful email marketing and automation platform.
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
email-subscribers
Add subscription forms on the website and send newsletters & automatically send post notification about new blog posts once it gets published.
CleverReach® WP Developer Profile
3 plugins · 6K total installs
How We Detect CleverReach® WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cleverreach-wp/resources/css/cleverreach.css/wp-content/plugins/cleverreach-wp/resources/js/cleverreach.backend.js/wp-content/plugins/cleverreach-wp/resources/js/cleverreach.frontend.js/wp-content/plugins/cleverreach-wp/resources/js/cleverreach.gutenberg-block.js/wp-content/plugins/cleverreach-wp/resources/js/cleverreach.backend.js/wp-content/plugins/cleverreach-wp/resources/js/cleverreach.frontend.js/wp-content/plugins/cleverreach-wp/resources/js/cleverreach.gutenberg-block.jscleverreach-wp/resources/css/cleverreach.css?ver=cleverreach-wp/resources/js/cleverreach.backend.js?ver=cleverreach-wp/resources/js/cleverreach.frontend.js?ver=cleverreach-wp/resources/js/cleverreach.gutenberg-block.js?ver=HTML / DOM Fingerprints
cleverreach-subscribe-form-wrappercleverreach-wp-widget-containercleverreach-frontend-form<!-- CleverReach Form Start --><!-- CleverReach Form End -->data-cleverreach-form-iddata-cleverreach-render-formwindow.CleverReach[cleverreach_subscription_form]