Fast MailerLite Security & Risk Analysis

wordpress.org/plugins/fast-mailerlite

Easily Sync MailerLite Contacts With Your WordPress Users.

400 active installs v1.1.3 PHP 7.4+ WP 4.0+ Updated Aug 9, 2023
email-automationemail-marketingmailer-litemailerlitemarketing-automation
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fast MailerLite Safe to Use in 2026?

Generally Safe

Score 85/100

Fast MailerLite has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "fast-mailerlite" v1.1.3 plugin exhibits several concerning security practices, despite a clean vulnerability history. The most significant issue is the presence of two AJAX handlers that lack any authentication or capability checks. This creates a substantial attack surface, as unauthorized users could potentially trigger these handlers, leading to unintended actions or information disclosure. The use of the `unserialize` function, a known risk if not handled with extreme care regarding input source, also raises a red flag. Although the taint analysis did not reveal critical or high severity flows, the existence of a flow with unsanitized paths warrants attention, indicating potential for vulnerabilities if the input is not properly validated. The plugin's strong reliance on external HTTP requests (11) also introduces a dependency on the security of those external services. However, the plugin does demonstrate some good practices, such as a relatively high percentage of SQL queries using prepared statements and a good rate of output escaping. The absence of any recorded CVEs is a positive sign, suggesting that, to date, no publicly known vulnerabilities have been discovered. Overall, while the lack of past vulnerabilities is encouraging, the identified code-level weaknesses, particularly the unprotected AJAX endpoints, necessitate careful consideration and mitigation.

Key Concerns

  • AJAX handlers without auth checks
  • Presence of unserialize function
  • Flows with unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Fast MailerLite Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fast MailerLite Code Analysis

Dangerous Functions
4
Raw SQL Queries
2
4 prepared
Unescaped Output
1
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
11
Bundled Libraries
0

Dangerous Functions Found

unserialize$mailerlite_options = empty( $mailerlite_db->settings_data ) ? array() : unserialize( $mailerlite_dbfast-mailerlite.php:54
unserialize$aroptions = unserialize($pdata->aroptions);fast-mailerlite.php:152
unserialize$mailerlite_options = empty( $mailerlite_db->settings_data ) ? array() : unserialize( $mailerlite_dbfast-mailerlite.php:155
unserialize$mailerlite_options = empty( $mailerlite_db->settings_data ) ? array() : unserialize( $mailerlite_dbfast-mailerlite.php:620

SQL Query Safety

67% prepared6 total queries

Output Escaping

75% escaped4 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<fast-mailerlite> (fast-mailerlite.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Fast MailerLite Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_fastflow_mailerlite_group_subscriber_syncfast-mailerlite.php:39
authwp_ajax_fastflow_mailerlite_group_subscriber_syncfast-mailerlite.php:40
WordPress Hooks 13
actionadmin_noticesfast-mailerlite.php:27
filterff_settingsfast-mailerlite.php:28
filterff_settings_datafast-mailerlite.php:29
filterFM_AR_select_options_addonsfast-mailerlite.php:30
filterFM_AR_options_HTML_addonsfast-mailerlite.php:31
actionFM_add_to_AR_addonsfast-mailerlite.php:32
actionuser_registerfast-mailerlite.php:33
actionprofile_updatefast-mailerlite.php:34
actionFM_after_member_registeredfast-mailerlite.php:35
actionFM_after_transaction_recordedfast-mailerlite.php:36
actionafter_tag_applied_hookfast-mailerlite.php:37
actionadmin_footerfast-mailerlite.php:38
actionFF_add_to_AR_addonsfast-mailerlite.php:41
Maintenance & Trust

Fast MailerLite Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedAug 9, 2023
PHP min version7.4
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs400
Developer Profile

Fast MailerLite Developer Profile

fastflow

14 plugins · 940 total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
432 days
View full developer profile
Detection Fingerprints

How We Detect Fast MailerLite

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fast-mailerlite/fast-mailerlite-admin.css/wp-content/plugins/fast-mailerlite/fast-mailerlite-admin.js/wp-content/plugins/fast-mailerlite/fast-mailerlite-webhook.php
Script Paths
/wp-content/plugins/fast-mailerlite/fast-mailerlite-admin.js
Version Parameters
fast-mailerlite/fast-mailerlite-admin.css?ver=fast-mailerlite/fast-mailerlite-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
arcontentboxitem-tab-box
Data Attributes
id="fastflow_mailerlite_apikey"id="fastflow_mailerlite_sync_btn"id="arbox11"id="mailerlite_group_id"
JS Globals
fastflow_mailerlite_group_subscriber_sync
FAQ

Frequently Asked Questions about Fast MailerLite