E-mail Campaign Manager Security & Risk Analysis

wordpress.org/plugins/e-mail-campaign-manager

Requires at least: 3.0.1 Tested up to: 4.8 Donate link: https://www.paypal.me/r1mediapl Stable tag: 1.9 License: GPLv2 or later License URI: http://ww …

10 active installs v1.9 PHP + WP + Updated Unknown
e-mail-campaign-managere-mail-liste-mail-manageremail-listsubscription-manager
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is E-mail Campaign Manager Safe to Use in 2026?

Generally Safe

Score 100/100

E-mail Campaign Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The e-mail-campaign-manager plugin v1.9 demonstrates a mixed security posture. On the positive side, there are no known vulnerabilities (CVEs) associated with this plugin, and it employs nonce checks, indicating a general awareness of security best practices. The absence of dangerous functions, file operations, and external HTTP requests are also strengths. However, significant concerns arise from the static analysis. A substantial portion of SQL queries are not using prepared statements (40% unsanitized), presenting a risk of SQL injection. Furthermore, only 13% of output escaping is properly handled, which is a very low percentage and indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis reveals flows with unsanitized paths, although no critical or high severity issues were flagged, this still warrants attention.

The plugin's vulnerability history is clean, which is positive. However, the static analysis findings, particularly the high percentage of unescaped output and raw SQL queries, suggest that the lack of past vulnerabilities might be due to luck or limited previous scrutiny rather than inherent robust security. The plugin's strengths lie in its lack of known historical exploits and the presence of some basic security measures like nonce checks. The primary weaknesses are the numerous potential injection and XSS vulnerabilities identified through static analysis.

Key Concerns

  • High percentage of raw SQL queries
  • Very low percentage of properly escaped output
  • Taint flows with unsanitized paths
Vulnerabilities
None known

E-mail Campaign Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

E-mail Campaign Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
6 prepared
Unescaped Output
129
19 escaped
Nonce Checks
10
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

40% prepared15 total queries

Output Escaping

13% escaped148 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

9 flows3 with unsanitized paths
<campaigns> (views\campaigns.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

E-mail Campaign Manager Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[email-camp-manager] email-campaign-manager.php:124
[email-camp-validation] email-campaign-manager.php:134
[email-camp-activation] email-campaign-manager.php:144
[email-camp-unsubscribe] email-campaign-manager.php:154
WordPress Hooks 3
actionadmin_menuemail-campaign-manager.php:15
actionadmin_initemail-campaign-manager.php:16
actionadmin_enqueue_scriptsemail-campaign-manager.php:52
Maintenance & Trust

E-mail Campaign Manager Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

E-mail Campaign Manager Developer Profile

Roman Cieciuch

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect E-mail Campaign Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/e-mail-campaign-manager/css/style.css
Version Parameters
e-mail-campaign-manager/css/style.css?ver=1

HTML / DOM Fingerprints

CSS Classes
r1-campaign-manageractive
HTML Comments
Plugin Name: E-mail Campaign ManagerPlugin URI: https://abckodera.pl/aktualnosci/e-mail-campaign-manager/Description: Managing Your e-mail subscriptions made easy.Version: 1.9+6 more
Data Attributes
name="ecm_name"name="ecm_email"name="ecm_captcha"name="ecm_securityHash"name="ecm_campaignID"
Shortcode Output
<form method="post" action="<h2><input type="text" name="ecm_name" placeholder="Name" required="required" /><input type="email" name="ecm_email" placeholder="E-mail" required="required" />
FAQ

Frequently Asked Questions about E-mail Campaign Manager