
Email and SMS marketing for WordPress by DailyStory Security & Risk Analysis
wordpress.org/plugins/dailystoryDailyStory automates outbound sales, client engagement, and follow-up in order to generate interest at the top of the sales funnel.
Is Email and SMS marketing for WordPress by DailyStory Safe to Use in 2026?
Generally Safe
Score 92/100Email and SMS marketing for WordPress by DailyStory has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dailystory" v2.1.6 plugin exhibits a generally positive security posture, with no known vulnerabilities (CVEs) or critical issues identified in the static analysis. The plugin demonstrates good practice by utilizing prepared statements for all SQL queries and avoiding dangerous functions. The attack surface is relatively small, consisting of only three shortcodes, and notably, there are no unprotected entry points in terms of AJAX handlers or REST API routes. The absence of critical severity taint flows is also a strong indicator of secure coding. However, a significant concern arises from the low percentage of properly escaped outputs (33%). This indicates that sensitive data displayed to users might be susceptible to cross-site scripting (XSS) attacks if not handled carefully by the content displayed within the shortcodes. Additionally, the plugin makes an external HTTP request, the security implications of which are not detailed but represent a potential vector for data leakage or man-in-the-middle attacks if not properly secured. The complete lack of nonce checks and capability checks across all entry points is a notable weakness, as it leaves the shortcode functionality potentially vulnerable to CSRF (Cross-Site Request Forgery) attacks if those shortcodes perform any sensitive actions. Despite these areas for improvement, the plugin's foundation is solid, with no immediate critical threats apparent from the provided data.
Key Concerns
- Unescaped output is low
- No nonce checks
- No capability checks
- External HTTP request
Email and SMS marketing for WordPress by DailyStory Security Vulnerabilities
Email and SMS marketing for WordPress by DailyStory Release Timeline
Email and SMS marketing for WordPress by DailyStory Code Analysis
Output Escaping
Email and SMS marketing for WordPress by DailyStory Attack Surface
Shortcodes 3
WordPress Hooks 7
Maintenance & Trust
Email and SMS marketing for WordPress by DailyStory Maintenance & Trust
Maintenance Signals
Community Trust
Email and SMS marketing for WordPress by DailyStory Alternatives
Account Engagement
pardot
Integrate Account Engagement with WordPress: easily track visitors, embed forms and dynamic content in pages and posts, or use the forms or dynamic co …
Convesio Convert – WooCommerce Email Marketing Automation with Website Personalization, Popups and Forms
marketing-automation-and-personalization
Sell more with less effort using personalized marketing automation, email, popups, forms, dynamic webpages, and advanced customer segmentation.
YayBoost – Sales Booster for WooCommerce
yayboost-sales-booster-for-woocommerce
Boost conversions, increase AOV, and create urgency with powerful sales-boosting tools for WooCommerce.
BROSH CRM
brosh-crm
BROSH - THE ALL-IN-ONE BUSINESS SUITE, THE ULTIMATE SOLUTION FOR SME!
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Email and SMS marketing for WordPress by DailyStory Developer Profile
2 plugins · 30 total installs
How We Detect Email and SMS marketing for WordPress by DailyStory
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dailystory/assets/css/dailystory.css/wp-content/plugins/dailystory/assets/js/dailystory.jshttps://pages.dailystory.com/bundles/dailystory-landingpage.min.jshttps://cdn.jsdelivr.net/npm/intl-tel-input@18.2.7/build/js/intlTelInput.min.jshttps://cdn.jsdelivr.net/npm/intl-tel-input@18.2.7/build/js/utils.jsdailystory/style.css?ver=dailystory/script.js?ver=HTML / DOM Fingerprints
dailystory-popupdailystory-webformAdded by WordPress shortcodedata-dailystory-tenant-uiddata-dailystory-webform-iddata-dailystory-popup-idDs.Pop.showPopupOnExitDs.Pop.showPopupdailystory_settingsDAILYSTORY_SHORTCODE_PATHDAILYSTORY_PLUGIN_PATHDAILYSTORY_PLUGIN_SLUG+1 more[ds-webform[ds-exitintent[ds-popup