
Epicwin Plugin Security & Risk Analysis
wordpress.org/plugins/epicwin-subscribersThis plugin allows your blog visitors to subscribe to your blog via email and receive notifications whenever you create a new post.
Is Epicwin Plugin Safe to Use in 2026?
Use With Caution
Score 63/100Epicwin Plugin has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'epicwin-subscribers' plugin v1.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries, utilizing prepared statements exclusively. There are no external HTTP requests, which generally reduces the attack surface related to external services. The plugin also has a relatively small attack surface in terms of direct entry points like AJAX handlers, REST API routes, and shortcodes.
However, significant concerns arise from the code analysis. The very low percentage of properly escaped output (5%) is a major red flag, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of one taint flow with unsanitized paths and a high severity taint analysis result further reinforces this concern, suggesting that user-controlled data might be processed in an unsafe manner, potentially leading to code injection or other critical issues. The complete lack of nonce checks on any entry points, coupled with only one capability check, leaves the plugin highly susceptible to Cross-Site Request Forgery (CSRF) attacks, especially if any of its functionalities can be triggered by unauthenticated or less privileged users.
The vulnerability history, with one currently unpatched medium severity CVE originating from CSRF, aligns with the findings from the code analysis. The past prevalence of CSRF vulnerabilities suggests a recurring pattern of insufficient protection against malicious requests. While the plugin has no critical or high CVEs and avoids raw SQL, the substantial risk of XSS and CSRF due to poor output escaping and lack of proper authorization/validation mechanisms significantly outweighs its strengths. This plugin requires immediate attention to address these critical security weaknesses.
Key Concerns
- High risk of XSS due to low output escaping
- Unsanitized path taint flow (high severity)
- Missing nonce checks on entry points
- Unpatched medium severity CVE
- Limited capability checks
Epicwin Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Epicwin Plugin <= 1.5 - Cross-Site Request Forgery to SQL Injection
Epicwin Plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Epicwin Plugin Attack Surface
WordPress Hooks 6
Maintenance & Trust
Epicwin Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Epicwin Plugin Alternatives
Cartograf Featured-image in Feed
cartograf-featured-image-in-feed
Includes the featured image of a post at the beginning of the item's content in the WordPress generated feeds. With this plugin, you no longer ne …
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
fluent-crm
The easiest and fastest Email Marketing, Newsletter, Marketing Automation Plugin & CRM Solution for WordPress
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
email-subscribers
Add subscription forms on the website and send newsletters & automatically send post notification about new blog posts once it gets published.
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages
convertkit
Build your email subscriber lists, send email marketing newsletters, sell more products and build your membership site with Kit (formerly ConvertKit).
Simple Newsletter Plugin – Noptin
newsletter-optin-box
A fast, GDPR-compliant newsletter plugin. Collect newsletter subscribers, let users subscribe to new post notifications, and send newsletters. ★★★★★
Epicwin Plugin Developer Profile
1 plugin · 100 total installs
How We Detect Epicwin Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/epicwin-subscribers/style.cssHTML / DOM Fingerprints
epicwin-subscriptionwidget_epicwin_widgeterrorserrorsuccessname="sub_name"name="sub_email"name="action"value="subscribe"