
Plugin Name: CM Subscriber Stats Security & Risk Analysis
wordpress.org/plugins/cm-subscriber-statsSee your email list subscriber statistics on your WordPress dashboard.
Is Plugin Name: CM Subscriber Stats Safe to Use in 2026?
Generally Safe
Score 85/100Plugin Name: CM Subscriber Stats has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'cm-subscriber-stats' plugin version 1.0.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified vulnerabilities in its history and the clean taint analysis suggest a codebase that has either been very well-developed or has not been a target for exploitation. The plugin also demonstrates good practices by not exposing a large attack surface through AJAX handlers, REST API routes, or shortcodes without authorization. Furthermore, all SQL queries are using prepared statements, and there are no identified file operations or external HTTP requests that could be easily exploited.
However, a significant concern arises from the output escaping analysis, where 100% of the outputs are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the plugin has a capability check, the lack of proper output sanitization means that any user-supplied data that is displayed back to the user, without proper escaping, can be manipulated to execute arbitrary JavaScript in the context of the user's browser. The lack of nonce checks, while not immediately alarming given the limited attack surface, could become a weakness if new entry points are introduced in future versions without corresponding security measures.
In conclusion, the plugin's clean vulnerability history and well-managed entry points are positive indicators. Nevertheless, the critical issue of unescaped output presents a substantial risk that overshadows these strengths. Addressing the XSS vulnerability through robust output escaping is paramount to improving the plugin's security.
Key Concerns
- 100% of outputs are not properly escaped
Plugin Name: CM Subscriber Stats Security Vulnerabilities
Plugin Name: CM Subscriber Stats Code Analysis
Output Escaping
Plugin Name: CM Subscriber Stats Attack Surface
WordPress Hooks 3
Maintenance & Trust
Plugin Name: CM Subscriber Stats Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Name: CM Subscriber Stats Alternatives
Independent Analytics – Google Analytics Alternative for WordPress
independent-analytics
A simple WordPress analytics plugin that is privacy-friendly, fast, and an alternative to Google Analytics.
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
fluent-crm
The easiest and fastest Email Marketing, Newsletter, Marketing Automation Plugin & CRM Solution for WordPress
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
email-subscribers
Add subscription forms on the website and send newsletters & automatically send post notification about new blog posts once it gets published.
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages
convertkit
Build your email subscriber lists, send email marketing newsletters, sell more products and build your membership site with Kit (formerly ConvertKit).
weMail: Email Marketing, Email Automation, Newsletters, Subscribers & eCommerce Email Optins
wemail
Send email newsletters, automate email marketing with email automation, manage subscribers, eCommerce emails, post notifications & optins with ease
Plugin Name: CM Subscriber Stats Developer Profile
3 plugins · 290 total installs
How We Detect Plugin Name: CM Subscriber Stats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cm-subscriber-stats/css/style.css/wp-content/plugins/cm-subscriber-stats/js/script.js/wp-content/plugins/cm-subscriber-stats/js/script.jscm-subscriber-stats/css/style.css?ver=cm-subscriber-stats/js/script.js?ver=HTML / DOM Fingerprints
rss-widgetrssSummary