
List Builder Security & Risk Analysis
wordpress.org/plugins/email-list-builder-by-social-intentsList Builder is the easiest way to double your email subscribers. A lightbox that integrates with MailChimp, Campaign Monitor, Constant Contact.
Is List Builder Safe to Use in 2026?
Generally Safe
Score 85/100List Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'email-list-builder-by-social-intents' v1.6.69 exhibits a generally strong security posture based on the provided static analysis. There are no identified critical or high-severity vulnerabilities in the code analysis, including no dangerous functions, no external HTTP requests, and all SQL queries utilize prepared statements. Furthermore, the plugin has a history of zero known vulnerabilities, suggesting a commitment to security or a lack of complex features that typically attract exploits. However, a significant concern is the complete lack of output escaping across all identified output points. This represents a major weakness that could potentially lead to cross-site scripting (XSS) vulnerabilities if any user-supplied data is displayed without proper sanitization. The absence of any identified attack surface entry points is positive, but the lack of escaping overshadows this strength.
While the plugin boasts a clean vulnerability history and secure coding practices like prepared statements, the critical flaw in output escaping cannot be overlooked. This lack of sanitization poses a direct risk to users, allowing for potential XSS attacks. The absence of identified taint flows and dangerous functions is reassuring, but the identified output escaping issue is a clear and present danger. In conclusion, despite a good foundation with prepared statements and no known CVEs, the critical deficiency in output escaping makes this plugin a moderate risk, requiring immediate attention to address the potential for XSS vulnerabilities.
Key Concerns
- No output escaping
List Builder Security Vulnerabilities
List Builder Code Analysis
Output Escaping
List Builder Attack Surface
WordPress Hooks 5
Maintenance & Trust
List Builder Maintenance & Trust
Maintenance Signals
Community Trust
List Builder Alternatives
Export Comment Author Emails – Build email list
export-comment-author-emails
Export email address list from existing comments on your website. Export comment authors' name, email address and website url as CSV or Text file …
YITH WooCommerce Waitlist
yith-woocommerce-waiting-list
This plugin enables registered users to request an email notification when an out-of-stock product comes back into stock.
Newsletters
newsletters-lite
Newsletter plugin for WordPress to capture subscribers and send beautiful, bulk newsletter emails.
Benchmark Email Lite
benchmark-email-lite
Your Wordpress Site and Email Marketing all in one place!
Contact Form 7 GetResponse Extension
contact-form-7-getresponse-extension
A very easy plugin to integrate GetResponse campaigns with Contact Form 7.
List Builder Developer Profile
5 plugins · 540 total installs
How We Detect List Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/email-list-builder-by-social-intents/socialintents.pngsiJsHost+'www.socialintents.com/api/email/socialintents.js#'.get_option('elb_widgetID')HTML / DOM Fingerprints
elb_noAccountSpanelb_registerelb_registerComplete<!-- Email List Builder from www.socialintents.com -->id="dashboardiframe"id="elb_widgetID"id="elb_email"id="elb_name"id="elb_password"id="elb_inputRegister"+5 morewindow.attachEventwindow.addEventListenervar siJsHostvar svar x<iframe id="dashboardiframe" src="https://www.socialintents.com/dashboard.do" height=500 width=98% scrolling="yes"></iframe><a href="https://www.socialintents.com/dashboard.do" target="_newWindow" onClick="javascript:document.getElementById('dashboarddiv').innerHTML=''; ">Open Email List Builder by Social Intents in a new window</a>.