Email Blaster Newsletter Signup Form Security & Risk Analysis

wordpress.org/plugins/email-blaster-newsletter-signup-form

Email subscribe forms for your website. Send HTML email marketing (newsletters). GDPR compliant, UK based email marketing and email automation.

100 active installs v1.0.7 PHP + WP 2.3+ Updated Apr 8, 2019
email-marketingemail-newsletter-formgdpropt-insubscription
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Email Blaster Newsletter Signup Form Safe to Use in 2026?

Generally Safe

Score 85/100

Email Blaster Newsletter Signup Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "email-blaster-newsletter-signup-form" plugin version 1.0.7 exhibits a seemingly strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly limits the potential attack surface. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is a positive indicator. The use of prepared statements for all SQL queries is excellent practice. However, a significant concern arises from the extremely low percentage (22%) of properly escaped output, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of nonce and capability checks across all entry points, coupled with the complete absence of taint analysis results, suggests that security testing might have been incomplete or is not being rigorously applied to potential data handling. The plugin's vulnerability history is clean, which is positive, but this cannot offset the identified output escaping and authorization control weaknesses.

Key Concerns

  • Low output escaping percentage (22%)
  • No nonce checks found
  • No capability checks found
  • Taint analysis data unavailable/zero flows
Vulnerabilities
None known

Email Blaster Newsletter Signup Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Email Blaster Newsletter Signup Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

22% escaped9 total outputs
Attack Surface

Email Blaster Newsletter Signup Form Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initindex.php:65
Maintenance & Trust

Email Blaster Newsletter Signup Form Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedApr 8, 2019
PHP min version
Downloads17K

Community Trust

Rating80/100
Number of ratings4
Active installs100
Developer Profile

Email Blaster Newsletter Signup Form Developer Profile

emailblaster

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Email Blaster Newsletter Signup Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/email-blaster-newsletter-signup-form/resources/emailblaster.min.js
Script Paths
/wp-content/plugins/email-blaster-newsletter-signup-form/resources/emailblaster.min.js
Version Parameters
email-blaster-newsletter-signup-form/resources/emailblaster.min.js?rev=

HTML / DOM Fingerprints

CSS Classes
emailblasterwidgetEmailBlasterWidgetEmailBlasterForm
HTML Comments
<!-- Plugin Name: Email Subscribe Form & Newsletter Builder Plugin URI: http://www.emailblasteruk.com/wordpress Description: The official Email Blaster Widget. Add a newsletter signup form or contact forms to your WordPress site. + Use the power of Email Blaster to email your subscribers. Getting Started: 1) Click the "Activate" link to the left of this description. 2) <a href="https://emailblaster.cloud/landing/wordpress">Sign up and build your form.</a> 3) Go to your <a href="/wp-admin/widgets.php">Widgets area</a> and enter your QuickCode. <a href="https://www.youtube.com/watch?v=p__Th95VewQ">Need more help?</a>. Author: Email Blaster Author URI: http://www.emailblasteruk.com Version: 1.0.7 This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version. This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License along with this program. If not, see <http://www.gnu.org/licenses/>. -->[Email Blaster] Generate Submitted Embed Code[Email Blaster] Determine If Subscribe/Form Builder[Email Blaster] Echo Output
Data Attributes
emailblasterwidget
Shortcode Output
<div class="EmailBlasterWidget"><iframe src="" width="100%" scrolling="no" frameborder="0" class="EmailBlasterForm"></iframe></div>
FAQ

Frequently Asked Questions about Email Blaster Newsletter Signup Form