
WP-Admin Distribution List Security & Risk Analysis
wordpress.org/plugins/distributionlistSend emails to members in your Connections plugin
Is WP-Admin Distribution List Safe to Use in 2026?
Generally Safe
Score 85/100WP-Admin Distribution List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The distributionlist plugin v0.3 exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, file operations, external HTTP requests, and correctly using prepared statements for its SQL queries, significant concerns arise from its attack surface and output handling. The plugin has one AJAX handler that lacks any authentication checks, presenting a direct entry point for potential exploitation. Furthermore, a critical flaw is identified in the taint analysis, with a flow involving unsanitized paths, which could lead to various injection vulnerabilities if not properly handled. The absence of any output escaping for all identified output points is a serious weakness, making it susceptible to Cross-Site Scripting (XSS) attacks. The plugin's vulnerability history is clean, with no recorded CVEs, which is positive. However, this lack of history, coupled with the identified code weaknesses, might indicate a lack of thorough security testing or a limited track record rather than inherent robustness. The plugin's strengths lie in its careful handling of database queries and its avoidance of certain risky coding patterns. However, the unprotected AJAX endpoint and pervasive lack of output escaping represent substantial risks that require immediate attention. The unsanitized path flow in the taint analysis is also a significant concern that needs to be addressed to prevent potential injection attacks.
Key Concerns
- AJAX handler without auth checks
- Flow with unsanitized paths
- 100% of outputs unescaped
- No nonce checks
- No capability checks
WP-Admin Distribution List Security Vulnerabilities
WP-Admin Distribution List Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-Admin Distribution List Attack Surface
AJAX Handlers 1
WordPress Hooks 1
Maintenance & Trust
WP-Admin Distribution List Maintenance & Trust
Maintenance Signals
Community Trust
WP-Admin Distribution List Alternatives
Participants Database
participants-database
Build and maintain a fully customizable database of participants, members or anything with signup forms, admin backend, custom lists, and CSV support.
Newsletters
newsletters-lite
Newsletter plugin for WordPress to capture subscribers and send beautiful, bulk newsletter emails.
Benchmark Email Lite
benchmark-email-lite
Your Wordpress Site and Email Marketing all in one place!
Contact Form 7 GetResponse Extension
contact-form-7-getresponse-extension
A very easy plugin to integrate GetResponse campaigns with Contact Form 7.
Email Marketing Plugin – WP Email Capture
wp-email-capture
Double opt-in form for building your email list. Define landing pages to distribute your ebooks & software.
WP-Admin Distribution List Developer Profile
3 plugins · 520 total installs
How We Detect WP-Admin Distribution List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/distributionlist/asset/css/bootstrap.min.css/wp-content/plugins/distributionlist/asset/js/bootstrap.min.jsHTML / DOM Fingerprints
alertalert-dangerpagedbtn-grouppaginatebtnbtn-primaryform-control+1 moredata-idajaxurltinyMCE/wp-json/wpadmin/v1/sendMail_ajax_request<div class='alert alert-danger'><b>This plugin requires the 'Connections Business Directory' plugin.</b><p>Please install <a href='#' class='connections'>'Connections Business Directory'</a> plugin to continue.</div><div class='btn-group' role='group' aria-label='Basic example'><div id=memberlist class='col-xs-12 col-sm-4'><div id=membermessage class='col-xs-12 col-sm-8'>