E-Newsletter Plugin für PROFFIX Security & Risk Analysis

wordpress.org/plugins/e-newsletter-proffix

Plugin für die einfache Nutzung des PROFFIX E-Newsletter Services in Wordpress.

10 active installs v1.0.1 PHP + WP 3.3.1+ Updated Feb 23, 2017
anmeldunge-newsletternewsletterproffixwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is E-Newsletter Plugin für PROFFIX Safe to Use in 2026?

Generally Safe

Score 85/100

E-Newsletter Plugin für PROFFIX has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The 'e-newsletter-proffix' plugin v1.0.1 exhibits a generally positive security posture based on the static analysis. It demonstrates good practices by having no direct SQL queries outside of prepared statements and no file operations, significantly reducing common attack vectors. The absence of known CVEs and a clean vulnerability history also points towards a well-maintained or less targeted plugin. However, there are notable areas for improvement that introduce potential risks.

The primary concern is the lack of explicit nonce checks and capability checks across the identified entry points. While the total number of entry points is low (one shortcode), the absence of these fundamental security mechanisms means that any user, regardless of their role or authorization, could potentially trigger the shortcode's functionality. Furthermore, the plugin makes an external HTTP request, which, without proper sanitization or validation of the target URL or data exchanged, could be exploited for various attacks like SSRF or data exfiltration if the request's parameters are influenced by user input.

While the 62% output escaping rate is not ideal, it's not a critical issue given the limited attack surface and lack of critical taint flows. The plugin's strengths lie in its avoidance of dangerous functions and raw SQL. The weaknesses, however, are concentrated in authorization and the potential risks associated with external HTTP requests. A balanced conclusion is that while the plugin is not overtly insecure, it has readily addressable vulnerabilities in its authorization and external communication that should be fortified.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • External HTTP request without clear sanitization context
  • Output escaping below 100%
Vulnerabilities
None known

E-Newsletter Plugin für PROFFIX Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

E-Newsletter Plugin für PROFFIX Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
26 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

62% escaped42 total outputs
Attack Surface

E-Newsletter Plugin für PROFFIX Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[proffixnewsletter] proffix-newsletter.php:40
WordPress Hooks 5
actionadmin_menuproffix-newsletter.php:28
actionwp_enqueue_scriptsproffix-newsletter.php:29
actionadmin_print_stylesproffix-newsletter.php:30
actionafter_setup_themeproffix-newsletter.php:35
actionwidgets_initproffix-newsletter.php:178
Maintenance & Trust

E-Newsletter Plugin für PROFFIX Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedFeb 23, 2017
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

E-Newsletter Plugin für PROFFIX Developer Profile

Pedrett IT+Web AG

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect E-Newsletter Plugin für PROFFIX

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/e-newsletter-proffix/js/widget.js/wp-content/plugins/e-newsletter-proffix/css/widget_settings.css
Script Paths
/wp-content/plugins/e-newsletter-proffix/js/widget.js

HTML / DOM Fingerprints

CSS Classes
proffixnewsletter-widget
Data Attributes
id="proffixnewsletter-widget"name="proffixnewsletter"
Shortcode Output
[proffixnewsletter][proffixnewsletter url=[proffixnewsletter db=[proffixnewsletter list=
FAQ

Frequently Asked Questions about E-Newsletter Plugin für PROFFIX