Earnware Connect Security & Risk Analysis

wordpress.org/plugins/earnware-connect

A plugin to connect any wordpress site to the Earnware Dashboard.

10 active installs v1.0.80 PHP 7.1.8+ WP 3.0.1+ Updated Oct 16, 2025
contactscrmearnwareemailesp
99
A · Safe
CVEs total1
Unpatched0
Last CVEAug 15, 2025
Safety Verdict

Is Earnware Connect Safe to Use in 2026?

Generally Safe

Score 99/100

Earnware Connect has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Aug 15, 2025Updated 5mo ago
Risk Assessment

The "earnware-connect" plugin v1.0.80 exhibits a generally strong security posture based on the static analysis. The complete absence of dangerous functions, raw SQL queries, and file operations is commendable. Furthermore, the high percentage of properly escaped output and the presence of nonce and capability checks suggest a developer conscious of common web vulnerabilities. The plugin's attack surface, while consisting of 8 shortcodes, is noted as having no unprotected entry points, which is a positive sign.

However, the plugin is not without its areas for improvement. The single external HTTP request, while not explicitly analyzed for security implications in the provided data, warrants careful consideration as it could potentially be a vector for certain types of attacks if not handled with extreme care. The lack of taint analysis results is also a minor concern, as it indicates that either no flows were found or the analysis was not comprehensive enough to identify potential issues. The vulnerability history, showing one medium severity CVE in the past, suggests that while the developer has addressed past issues, a historical pattern of a past vulnerability should not be entirely overlooked.

In conclusion, "earnware-connect" v1.0.80 demonstrates good development practices, particularly in areas like SQL sanitization and output escaping. The identified attack surface appears to be secured. The main areas to monitor would be the secure handling of the external HTTP request and a more thorough taint analysis if possible. The past medium-severity vulnerability indicates the need for continued vigilance and prompt patching of any future security advisories.

Key Concerns

  • Single medium severity CVE in history
  • External HTTP request present
  • No taint analysis results
Vulnerabilities
1

Earnware Connect Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-7651medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Earnware Connect <= 1.0.74 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 15, 2025 Patched in 1.0.75 (63d)
Code Analysis
Analyzed Mar 16, 2026

Earnware Connect Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
207 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

99% escaped209 total outputs
Attack Surface

Earnware Connect Attack Surface

Entry Points8
Unprotected0

Shortcodes 8

[ew_subform] includes\class-wp-ew.php:193
[ew_form] includes\class-wp-ew.php:194
[ew_hasrole] includes\class-wp-ew.php:195
[ew_singlevisit] includes\class-wp-ew.php:196
[ew_transform_url] includes\class-wp-ew.php:197
[ew_view_subscriber_data] includes\class-wp-ew.php:198
[ew_ccpa_url] includes\class-wp-ew.php:199
[ew_recaptcha] includes\class-wp-ew.php:200
WordPress Hooks 11
actionplugins_loadedincludes\class-wp-ew.php:147
actionadmin_enqueue_scriptsincludes\class-wp-ew.php:162
actionadmin_enqueue_scriptsincludes\class-wp-ew.php:163
actionadmin_enqueue_scriptsincludes\class-wp-ew.php:164
actionadmin_menuincludes\class-wp-ew.php:167
actionadmin_initincludes\class-wp-ew.php:174
actionadmin_post_verify_v2_recaptchaincludes\class-wp-ew.php:189
actionadmin_post_nopriv_verify_v2_recaptchaincludes\class-wp-ew.php:190
actionwp_enqueue_scriptsincludes\class-wp-ew.php:191
actionwp_enqueue_scriptsincludes\class-wp-ew.php:192
actiontemplate_redirectincludes\class-wp-ew.php:201
Maintenance & Trust

Earnware Connect Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 16, 2025
PHP min version7.1.8
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Earnware Connect Developer Profile

Earnware

1 plugin · 10 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
63 days
View full developer profile
Detection Fingerprints

How We Detect Earnware Connect

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/earnware-connect/admin/css/wp-ew-admin.css/wp-content/plugins/earnware-connect/admin/js/wp-ew-admin.js/wp-content/plugins/earnware-connect/admin/css/bootstrap.min.css/wp-content/plugins/earnware-connect/admin/css/earnware-custom.css/wp-content/plugins/earnware-connect/admin/js/bootstrap.bundle.min.js/wp-content/plugins/earnware-connect/admin/js/feather.min.js
Script Paths
admin/js/wp-ew-admin.jsadmin/js/bootstrap.bundle.min.jsadmin/js/feather.min.js
Version Parameters
earnware-connectwp-ew-adminearnware-connect-bootstrapearnware-connect-customearnware-connect-fontsearnware-connect-bootstrap-jsearnware-connect-feather

HTML / DOM Fingerprints

HTML Comments
<!-- Only load on our plugin's admin page --><!-- Enqueue Bootstrap CSS (bundled locally to avoid external dependencies) --><!-- Enqueue custom styles --><!-- Enqueue Google Fonts -->+8 more
JS Globals
feather.replace()
FAQ

Frequently Asked Questions about Earnware Connect