
EnvíaloSimple: Email Marketing y Newsletters Security & Risk Analysis
wordpress.org/plugins/envialosimple-email-marketing-y-newsletters-gratisEl plugin de EnvíaloSimple te permitirá crear y enviar Newsletters de calidad profesional, en minutos y directamente desde tu Wordpress.
Is EnvíaloSimple: Email Marketing y Newsletters Safe to Use in 2026?
Generally Safe
Score 90/100EnvíaloSimple: Email Marketing y Newsletters has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin 'envialosimple-email-marketing-y-newsletters-gratis' v2.4.5 exhibits a mixed security posture. While it boasts a large number of REST API entry points (31), importantly, none of them appear to be unprotected by permission callbacks, which is a strong security practice. The code also demonstrates good practices in output escaping (93%) and uses prepared statements for a significant portion of its SQL queries. However, the presence of a `unserialize` dangerous function, coupled with two critical taint flows, raises concerns about potential deserialization vulnerabilities if user-controlled data is not rigorously sanitized before being unserialized.
The vulnerability history reveals a concerning pattern with a total of 5 known CVEs, including high and medium severity issues like Unrestricted File Upload, CSRF, Deserialization of Untrusted Data, and Cross-Site Scripting. Although there are currently no unpatched CVEs, the recurring nature of these vulnerability types suggests a potential for undiscovered or newly introduced vulnerabilities in this codebase. The most recent vulnerability was identified only recently in April 2024, emphasizing the need for ongoing vigilance.
In conclusion, while the plugin has implemented some key security measures like permission checks on its REST API and good output escaping, the presence of dangerous functions, critical taint flows, and a history of diverse and serious vulnerabilities necessitate a cautious approach. Developers should prioritize addressing the identified taint flows and thoroughly review all deserialization points. Users should ensure they are using the latest patched versions and remain aware of the plugin's past security incidents.
Key Concerns
- Presence of 'unserialize' dangerous function
- Critical taint flow detected (2 instances)
- Known CVEs: 1 high, 4 medium
- Flows with unsanitized paths (11 instances)
- SQL queries: 50% not using prepared statements
EnvíaloSimple: Email Marketing y Newsletters Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
EnvíaloSimple: Email Marketing y Newsletters <= 2.2 - Reflected Cross-Site Scripting
EnvíaloSimple: Email Marketing y Newsletters <= 2.3 - Cross-Site Request Forgery to Arbitrary File Upload
EnvíaloSimple <= 2.2 - Cross-Site Request Forgery
EnvíaloSimple <= 2.1 Unauthenticated PHP Object Injection
EnvialoSimple: Email Marketing y Newsletters < 1.98 - Cross-Site Scripting
EnvíaloSimple: Email Marketing y Newsletters Release Timeline
EnvíaloSimple: Email Marketing y Newsletters Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
EnvíaloSimple: Email Marketing y Newsletters Attack Surface
REST API Routes 31
WordPress Hooks 23
Maintenance & Trust
EnvíaloSimple: Email Marketing y Newsletters Maintenance & Trust
Maintenance Signals
Community Trust
EnvíaloSimple: Email Marketing y Newsletters Alternatives
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Newsletter – Send awesome emails from WordPress
newsletter
An email marketing tool for your blog: subscription forms to create your lists with unlimited subscribers and newsletters.
Brevo – Email, SMS, Web Push, Chat, and more.
mailin
Turn your WordPress site into a marketing powerhouse. Grow your audience, boost engagement, and drive more sales with Brevo.
Newsletters, Email Marketing, SMS and Popups by Omnisend
omnisend
Newsletters, Email Marketing, Email Automation, Forms, Pop Up, SMS by Omnisend
EnvíaloSimple: Email Marketing y Newsletters Developer Profile
2 plugins · 2K total installs
How We Detect EnvíaloSimple: Email Marketing y Newsletters
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/styles/menu.css/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/styles/styles.css/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/grapes/css/grapes.min.css/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/grapes/preset/grapesjs-preset-newsletter.css/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/axios.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/vue.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/dual-listbox.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/datepicker/vue-datepicker.js+9 more/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/axios.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/vue.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/dual-listbox.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/datepicker/vue-datepicker.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/datepicker/es.js/wp-content/plugins/envialosimple-email-marketing-y-newsletters-gratis/assets/js/grapes/grapes.min.js+7 moreHTML / DOM Fingerprints
ES_PLUGIN_URL_BASE/wp-json/envialosimple/v1/campaigns/getall/wp-json/envialosimple/v1/campaigns/getbyid/wp-json/envialosimple/v1/campaigns/create/wp-json/envialosimple/v1/campaigns/edit/wp-json/envialosimple/v1/campaigns/delete/wp-json/envialosimple/v1/campaigns/sendpreview/wp-json/envialosimple/v1/campaigns/checkstatus/wp-json/envialosimple/v1/campaigns/send