
Earnware Connect Security & Risk Analysis
wordpress.org/plugins/earnware-connectA plugin to connect any wordpress site to the Earnware Dashboard.
Is Earnware Connect Safe to Use in 2026?
Generally Safe
Score 99/100Earnware Connect has a strong security track record. Known vulnerabilities have been patched promptly.
The "earnware-connect" plugin v1.0.80 exhibits a generally strong security posture based on the static analysis. The complete absence of dangerous functions, raw SQL queries, and file operations is commendable. Furthermore, the high percentage of properly escaped output and the presence of nonce and capability checks suggest a developer conscious of common web vulnerabilities. The plugin's attack surface, while consisting of 8 shortcodes, is noted as having no unprotected entry points, which is a positive sign.
However, the plugin is not without its areas for improvement. The single external HTTP request, while not explicitly analyzed for security implications in the provided data, warrants careful consideration as it could potentially be a vector for certain types of attacks if not handled with extreme care. The lack of taint analysis results is also a minor concern, as it indicates that either no flows were found or the analysis was not comprehensive enough to identify potential issues. The vulnerability history, showing one medium severity CVE in the past, suggests that while the developer has addressed past issues, a historical pattern of a past vulnerability should not be entirely overlooked.
In conclusion, "earnware-connect" v1.0.80 demonstrates good development practices, particularly in areas like SQL sanitization and output escaping. The identified attack surface appears to be secured. The main areas to monitor would be the secure handling of the external HTTP request and a more thorough taint analysis if possible. The past medium-severity vulnerability indicates the need for continued vigilance and prompt patching of any future security advisories.
Key Concerns
- Single medium severity CVE in history
- External HTTP request present
- No taint analysis results
Earnware Connect Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Earnware Connect <= 1.0.74 - Authenticated (Contributor+) Stored Cross-Site Scripting
Earnware Connect Code Analysis
Output Escaping
Earnware Connect Attack Surface
Shortcodes 8
WordPress Hooks 11
Maintenance & Trust
Earnware Connect Maintenance & Trust
Maintenance Signals
Community Trust
Earnware Connect Alternatives
Apricotrocket CRM Plugin
apricot-rocket-crm
Make your website interactive by adding an integrated CRM database, custom forms, email newsletters, marketing automation and drip marketing tool.
RainmakerMoxie
rainmakermoxie
RainmakerMoxie (BETA-limited support) is an interactive sidebar widget. Enter an email address and it displays a photo, name, social links and more.
SaleGen Marketing Toolkit
salegen-marketing-toolkit
Form, Popup, Email Marketing Builder with built-in Contacts CRM. Capture leads and send campaigns without third-party services.
WP Centrico
wp-centrico
This plugin allows you to manage the subscription to centrico, your users will be registered in centrico and will receive your newsletter.
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
fluent-crm
The easiest and fastest Email Marketing, Newsletter, Marketing Automation Plugin & CRM Solution for WordPress
Earnware Connect Developer Profile
1 plugin · 10 total installs
How We Detect Earnware Connect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/earnware-connect/admin/css/wp-ew-admin.css/wp-content/plugins/earnware-connect/admin/js/wp-ew-admin.js/wp-content/plugins/earnware-connect/admin/css/bootstrap.min.css/wp-content/plugins/earnware-connect/admin/css/earnware-custom.css/wp-content/plugins/earnware-connect/admin/js/bootstrap.bundle.min.js/wp-content/plugins/earnware-connect/admin/js/feather.min.jsadmin/js/wp-ew-admin.jsadmin/js/bootstrap.bundle.min.jsadmin/js/feather.min.jsearnware-connectwp-ew-adminearnware-connect-bootstrapearnware-connect-customearnware-connect-fontsearnware-connect-bootstrap-jsearnware-connect-featherHTML / DOM Fingerprints
<!-- Only load on our plugin's admin page --><!-- Enqueue Bootstrap CSS (bundled locally to avoid external dependencies) --><!-- Enqueue custom styles --><!-- Enqueue Google Fonts -->+8 morefeather.replace()