Easy Email Subscription Security & Risk Analysis

wordpress.org/plugins/email-subscription-with-secure-captcha

Easy Email Subscription form with secured captcha.

30 active installs v1.3.1 PHP 5.6+ WP 3.6.1+ Updated Nov 3, 2025
captchaemail-subscribersemail-subscriptionemail-subscription-with-captchasimple-email-subscription
95
A · Safe
CVEs total3
Unpatched0
Last CVENov 11, 2025
Safety Verdict

Is Easy Email Subscription Safe to Use in 2026?

Generally Safe

Score 95/100

Easy Email Subscription has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Nov 11, 2025Updated 5mo ago
Risk Assessment

The email-subscription-with-secure-captcha plugin exhibits a mixed security posture. While it demonstrates good practices in its use of prepared statements for SQL queries (71%) and proper output escaping (91%), significant concerns arise from its attack surface. Two AJAX handlers are exposed without authentication checks, representing a direct vulnerability to unauthorized actions. The absence of critical or high severity taint flows is positive, suggesting that known pathways for immediate exploitation within the current version are limited.

However, the plugin's vulnerability history is a major red flag. With a total of 3 known CVEs, including one high severity and two medium severity vulnerabilities, it indicates a pattern of past security weaknesses. The common vulnerability types (XSS, CSRF, SQL Injection) suggest that the plugin has historically struggled with input validation and authorization. The fact that there are currently no unpatched vulnerabilities is a positive sign, but the historical data strongly suggests a need for vigilance and prompt updates.

In conclusion, while the current static analysis reveals fewer immediate critical flaws compared to some plugins, the exposed AJAX endpoints and the plugin's historical vulnerability record present notable risks. The presence of unprotected entry points coupled with a history of XSS, CSRF, and SQL Injection vulnerabilities means that users should remain cautious and ensure the plugin is always updated to the latest version.

Key Concerns

  • Unprotected AJAX handlers
  • Past high severity vulnerability
  • Past medium severity vulnerabilities
  • Total known CVEs
Vulnerabilities
3

Easy Email Subscription Security Vulnerabilities

CVEs by Year

3 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1
Medium
2

3 total CVEs

CVE-2025-11994high · 7.2Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Easy Email Subscription <= 1.3 - Unauthenticated Stored Cross-Site Scripting

Nov 11, 2025 Patched in 1.3.1 (1d)
CVE-2025-10691medium · 4.3Cross-Site Request Forgery (CSRF)

Easy Email Subscription <= 1.3 - Cross-Site Request Forgery to Arbitrary Subscriber Deletion

Nov 5, 2025 Patched in 1.3.1 (1d)
CVE-2025-10683medium · 4.9Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Easy Email Subscription <= 1.3 - Authenticated (Admin+) SQL Injection via uid

Nov 5, 2025 Patched in 1.3.1 (1d)
Code Analysis
Analyzed Mar 16, 2026

Easy Email Subscription Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
10 prepared
Unescaped Output
10
97 escaped
Nonce Checks
5
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

71% prepared14 total queries

Output Escaping

91% escaped107 total outputs
Data Flows
All sanitized

Data Flow Analysis

5 flows
sies_mainpage_show (simple-email-subscription.php:182)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Easy Email Subscription Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_sies_export_xlssimple-email-subscription.php:672
authwp_ajax_sies_export_csvsimple-email-subscription.php:699

Shortcodes 1

[sies_subc_form] subscriber-form.php:118
WordPress Hooks 10
filtertransient_pcc_scan_resultssimple-email-subscription.php:71
filterpre_set_transient_pcc_scan_resultssimple-email-subscription.php:72
filtersite_transient_pcc_scan_resultssimple-email-subscription.php:73
filterpre_set_site_transient_pcc_scan_resultssimple-email-subscription.php:74
filterwidget_textsimple-email-subscription.php:150
actionadmin_menusimple-email-subscription.php:176
actionadmin_menusimple-email-subscription.php:392
actioninitsimple-email-subscription.php:549
actionwidgets_initsimple-email-subscription.php:641
actionadmin_enqueue_scriptssimple-email-subscription.php:728
Maintenance & Trust

Easy Email Subscription Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 3, 2025
PHP min version5.6
Downloads5K

Community Trust

Rating60/100
Number of ratings2
Active installs30
Developer Profile

Easy Email Subscription Developer Profile

Yudiz Solutions Pvt. Ltd.

14 plugins · 6K total installs

85
trust score
Avg Security Score
96/100
Avg Patch Time
59 days
View full developer profile
Detection Fingerprints

How We Detect Easy Email Subscription

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/email-subscription-with-secure-captcha/assets/css/style.css/wp-content/plugins/email-subscription-with-secure-captcha/assets/js/scripts.js
Script Paths
/wp-content/plugins/email-subscription-with-secure-captcha/assets/js/scripts.js
Version Parameters
email-subscription-with-secure-captcha/assets/css/style.css?ver=email-subscription-with-secure-captcha/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
sies-form-wrapsies-form-emailsies-form-fullnamesies-form-submitsies-admin-page
Data Attributes
data-plugin-name="Easy Email Subscription"
JS Globals
window.sies_ajax_object
Shortcode Output
[easy_email_subscription]
FAQ

Frequently Asked Questions about Easy Email Subscription