Plugin Name: CM Subscriber Stats Security & Risk Analysis

wordpress.org/plugins/cm-subscriber-stats

See your email list subscriber statistics on your WordPress dashboard.

20 active installs v1.0.1 PHP + WP 2.7+ Updated Mar 3, 2009
campaign-monitordashboardemailstatisticssubscribers
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Plugin Name: CM Subscriber Stats Safe to Use in 2026?

Generally Safe

Score 85/100

Plugin Name: CM Subscriber Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 17yr ago
Risk Assessment

The 'cm-subscriber-stats' plugin version 1.0.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified vulnerabilities in its history and the clean taint analysis suggest a codebase that has either been very well-developed or has not been a target for exploitation. The plugin also demonstrates good practices by not exposing a large attack surface through AJAX handlers, REST API routes, or shortcodes without authorization. Furthermore, all SQL queries are using prepared statements, and there are no identified file operations or external HTTP requests that could be easily exploited.

However, a significant concern arises from the output escaping analysis, where 100% of the outputs are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the plugin has a capability check, the lack of proper output sanitization means that any user-supplied data that is displayed back to the user, without proper escaping, can be manipulated to execute arbitrary JavaScript in the context of the user's browser. The lack of nonce checks, while not immediately alarming given the limited attack surface, could become a weakness if new entry points are introduced in future versions without corresponding security measures.

In conclusion, the plugin's clean vulnerability history and well-managed entry points are positive indicators. Nevertheless, the critical issue of unescaped output presents a substantial risk that overshadows these strengths. Addressing the XSS vulnerability through robust output escaping is paramount to improving the plugin's security.

Key Concerns

  • 100% of outputs are not properly escaped
Vulnerabilities
None known

Plugin Name: CM Subscriber Stats Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Plugin Name: CM Subscriber Stats Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped5 total outputs
Attack Surface

Plugin Name: CM Subscriber Stats Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initcm-subscriber-stats.php:15
actionadmin_menucm-subscriber-stats.php:16
actionwp_dashboard_setupcm-subscriber-stats.php:17
Maintenance & Trust

Plugin Name: CM Subscriber Stats Maintenance & Trust

Maintenance Signals

WordPress version tested2.7
Last updatedMar 3, 2009
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Plugin Name: CM Subscriber Stats Developer Profile

Alex Dunae

3 plugins · 290 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Plugin Name: CM Subscriber Stats

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cm-subscriber-stats/css/style.css/wp-content/plugins/cm-subscriber-stats/js/script.js
Script Paths
/wp-content/plugins/cm-subscriber-stats/js/script.js
Version Parameters
cm-subscriber-stats/css/style.css?ver=cm-subscriber-stats/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
rss-widgetrssSummary
FAQ

Frequently Asked Questions about Plugin Name: CM Subscriber Stats