Fast Sendy Security & Risk Analysis

wordpress.org/plugins/fast-sendy

Integrate Sendy autoresponder with Fast Member. Add your Fast Member members to a Sendy list whenever they make a purchase.

0 active installs v1.1.1 PHP 7.4+ WP + Updated Aug 9, 2023
amazon-sesautoresponderemailemailingsendy
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Fast Sendy Safe to Use in 2026?

Generally Safe

Score 85/100

Fast Sendy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The fast-sendy v1.1.1 plugin exhibits a generally good security posture due to a very small attack surface and 100% output escaping. The absence of known CVEs and common vulnerability types in its history is a positive indicator. However, a significant concern arises from the presence of the `unserialize` function, which, without proper input validation or context, can lead to critical vulnerabilities like Remote Code Execution (RCE) or Object Injection if the serialized data originates from an untrusted source. Additionally, the complete lack of nonce checks across any entry points, while currently not a demonstrated problem due to the zero attack surface, represents a significant potential weakness if new entry points are introduced in the future without appropriate security measures. The plugin’s limited external HTTP requests and file operations also contribute positively to its security. Overall, the plugin benefits from a minimal attack surface and good output sanitization, but the `unserialize` function presents a latent but serious risk.

Key Concerns

  • Presence of unserialize() function
  • 0 Nonce checks on entry points
Vulnerabilities
None known

Fast Sendy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Fast Sendy Code Analysis

Dangerous Functions
1
Raw SQL Queries
1
2 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Dangerous Functions Found

unserialize$aroptions = unserialize($pdata[0]->aroptions);fast-sendy.php:90

SQL Query Safety

67% prepared3 total queries

Output Escaping

100% escaped1 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<fast-sendy> (fast-sendy.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Fast Sendy Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filterFM_AR_select_options_addonsfast-sendy.php:32
filterFM_AR_options_HTML_addonsfast-sendy.php:34
actionFM_add_to_AR_addonsfast-sendy.php:36
actionFF_add_to_AR_addonsfast-sendy.php:38
actionadmin_noticesfast-sendy.php:47
Maintenance & Trust

Fast Sendy Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedAug 9, 2023
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Fast Sendy Developer Profile

fastflow

14 plugins · 940 total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
432 days
View full developer profile
Detection Fingerprints

How We Detect Fast Sendy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fast-sendy/fast-sendy.php

HTML / DOM Fingerprints

CSS Classes
arcontentbox
Data Attributes
id='arbox7'
FAQ

Frequently Asked Questions about Fast Sendy