
Embed Sendy Security & Risk Analysis
wordpress.org/plugins/embed-sendyEmbed Sendy subscription form, through a widget, shortcode, or as a Gutenberg block.
Is Embed Sendy Safe to Use in 2026?
Generally Safe
Score 85/100Embed Sendy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The embed-sendy plugin v1.3.3 demonstrates some good security practices, such as using prepared statements for all SQL queries and the absence of known vulnerabilities. However, there are notable areas of concern. The static analysis reveals that 57% of output is properly escaped, which indicates a potential for cross-site scripting (XSS) vulnerabilities in the remaining 43% of outputs. Furthermore, the taint analysis identified two flows with unsanitized paths, classified as high severity. While these may not be directly exploitable due to a lack of explicit authentication checks on entry points, they represent potential avenues for attack if other security mechanisms were bypassed or misconfigured.
The plugin's vulnerability history is clean, with no recorded CVEs. This suggests a relatively stable and well-maintained codebase in terms of historical exploits. However, the absence of past vulnerabilities should not lead to complacency, especially given the findings in the static and taint analyses. The strengths lie in its SQL handling and lack of historical exploits. The weaknesses lie in the potential for unescaped output and identified high-severity taint flows that warrant further investigation to confirm their exploitability.
Key Concerns
- High severity unsanitized taint flows found
- Significant portion of output not properly escaped
Embed Sendy Security Vulnerabilities
Embed Sendy Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Embed Sendy Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Embed Sendy Maintenance & Trust
Maintenance Signals
Community Trust
Embed Sendy Alternatives
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets
widget-options
0ddcemmihs4a843ekhaoofzosrunf4bl Widget Options gives you super powers to control your site’s sidebar widgets and all Gutenberg blocks on pages, posts …
Advanced Import: One-Click Demo Import for WordPress
advanced-import
Advanced Import simplifies importing demo data for WordPress sites, enabling users to import posts, pages, media, widgets, customizer settings, and Gu …
Spotlight Social Feeds – Block, Shortcode, and Widget
spotlight-social-photo-feeds
Instagram feeds made easy. Responsive, customizable, accessible, and SEO-friendly out of the box. Includes Instagram blocks & oEmbed support.
Embed Sendy Developer Profile
3 plugins · 3K total installs
How We Detect Embed Sendy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/embed-sendy/assets/embed-sendy.css/wp-content/plugins/embed-sendy/assets/embed-sendy.jshttps://www.google.com/recaptcha/api.jsembed-sendy/assets/embed-sendy.css?ver=embed-sendy/assets/embed-sendy.js?ver=HTML / DOM Fingerprints
esd-form__rowesd-form__headeresd-form__footeresd-form__buttondata-listdata-recaptchaesdSettings/wp-json/embed-sendy/v1/process[embed_sendy][embed_sendy list="" recaptcha=""]