
Email Subscribers – Group Selector Security & Risk Analysis
wordpress.org/plugins/email-subscribers-advanced-formAdd-on for Email Subscribers plugin using which you can provide option to your users to select interested groups in the Subscribe Form.
Is Email Subscribers – Group Selector Safe to Use in 2026?
Generally Safe
Score 85/100Email Subscribers – Group Selector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "email-subscribers-advanced-form" plugin v1.5.1 exhibits a generally good security posture with no recorded vulnerabilities or critical issues identified in taint analysis. The high percentage of prepared SQL statements is a strong positive indicator of secure database interaction. The plugin also demonstrates a responsible approach to its limited attack surface, with no unprotected entry points found in the static analysis. The presence of nonce checks further enhances security by protecting against certain types of cross-site request forgery attacks.
However, a significant concern arises from the very low percentage of properly escaped output. With only 1% of 139 outputs being properly escaped, there is a high likelihood of cross-site scripting (XSS) vulnerabilities. This is further supported by the taint analysis, which found one flow with an unsanitized path, even though it wasn't classified as critical or high severity, suggesting a potential avenue for malicious input to be processed without adequate sanitization.
Given the absence of historical vulnerabilities, it might indicate diligent maintenance or that the plugin's functionality has not been a target. Nevertheless, the identified output escaping weakness is a serious concern that requires immediate attention. The plugin's strengths lie in its controlled attack surface and secure SQL practices, but the prevalent lack of output escaping poses a substantial risk that overshadows these positives.
Key Concerns
- Low percentage of properly escaped output
- Taint flow with unsanitized path
Email Subscribers – Group Selector Security Vulnerabilities
Email Subscribers – Group Selector Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Email Subscribers – Group Selector Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Email Subscribers – Group Selector Maintenance & Trust
Maintenance Signals
Community Trust
Email Subscribers – Group Selector Alternatives
Mailster WordPress Newsletter Plugin
mailster
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & …
MailUp for WordPress – Email and Newsletter Subscription Form
mailup-email-and-newsletter-subscription-form
Il plugin permette di inserire sul proprio sito WordPress un form per l’iscrizione degli utenti a newsletter, campagne email e SMS.
Email Blaster Newsletter Signup Form
email-blaster-newsletter-signup-form
Email subscribe forms for your website. Send HTML email marketing (newsletters). GDPR compliant, UK based email marketing and email automation.
Formilla Edge Targeted Messaging Platform for Sales and Marketing
formilla-edge
Target customers with the right message at the right time using Formilla Edge email, live chat, and in-app messaging.
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
Email Subscribers – Group Selector Developer Profile
8 plugins · 84K total installs
How We Detect Email Subscribers – Group Selector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/email-subscribers-advanced-form/assets/css/styles.css/wp-content/plugins/email-subscribers-advanced-form/includes/form/setting.jsemail-subscribers-advanced-form/assets/css/styles.css?ver=email-subscribers-advanced-form/includes/form/setting.js?ver=HTML / DOM Fingerprints
es-gdpr-admin-btnes-gdpr-admin-btn-secondarydata-esaf_form_titledata-esaf_settings_delete_recordesaf_settings_notices[email-subscribers-advanced-form]