Subscription Form for Feedblitz Security & Risk Analysis

wordpress.org/plugins/feedblitz-email-subscription

The best way to keep up with your content feed by placing a FeedBlitz Subscription Form widget or shortcode on your site.

70 active installs v1.0.9 PHP + WP 4.7+ Updated Sep 19, 2018
emailfeedfeed-pluginfeedblitzfeedblitz-plugin
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEApr 1, 2025
Safety Verdict

Is Subscription Form for Feedblitz Safe to Use in 2026?

Use With Caution

Score 64/100

Subscription Form for Feedblitz has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Apr 1, 2025Updated 7yr ago
Risk Assessment

The static analysis of feedblitz-email-subscription v1.0.9 reveals a generally strong security posture, with no identified dangerous functions, SQL injection vulnerabilities, or file operation risks. All identified SQL queries utilize prepared statements, and output appears to be properly escaped. The attack surface is also remarkably small, with zero entry points identified in AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, none of these are unprotected. Taint analysis also found no issues, indicating a lack of unsanitized data flows.

However, the plugin has a notable vulnerability history, with one known medium-severity CVE related to Cross-Site Scripting (XSS) that remains unpatched. This single unpatched vulnerability significantly impacts the overall security assessment, suggesting that despite good development practices in the current version, a past vulnerability has not been addressed. The absence of this CVE in the "currently unpatched" section of the vulnerability history is a concern, as is the recent date of the last vulnerability. While the code itself appears clean in this version, the past XSS issue warrants careful consideration and suggests a potential for recurring security weaknesses or a lack of timely patch management.

In conclusion, feedblitz-email-subscription v1.0.9 demonstrates excellent secure coding practices in its static analysis. The complete absence of attack surface and secure handling of code signals are commendable. However, the presence of an unpatched medium-severity XSS vulnerability from the past, dated recently, introduces a significant risk that overshadows the otherwise strong static analysis. Users should prioritize addressing this known vulnerability.

Key Concerns

  • Unpatched medium vulnerability (CVE)
Vulnerabilities
1

Subscription Form for Feedblitz Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31745medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Subscription Form for Feedblitz <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 1, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Subscription Form for Feedblitz Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Subscription Form for Feedblitz Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

Subscription Form for Feedblitz Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedSep 19, 2018
PHP min version
Downloads6K

Community Trust

Rating84/100
Number of ratings5
Active installs70
Developer Profile

Subscription Form for Feedblitz Developer Profile

Arni Cinco

3 plugins · 10K total installs

54
trust score
Avg Security Score
64/100
Avg Patch Time
659 days
View full developer profile
Detection Fingerprints

How We Detect Subscription Form for Feedblitz

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/feedblitz-email-subscription/feedblitz_email_subscription.css/wp-content/plugins/feedblitz-email-subscription/feedblitz_email_subscription.js
Script Paths
/wp-content/plugins/feedblitz-email-subscription/feedblitz_email_subscription.js
Version Parameters
feedblitz-email-subscription/feedblitz_email_subscription.css?ver=feedblitz-email-subscription/feedblitz_email_subscription.js?ver=

HTML / DOM Fingerprints

CSS Classes
feedblitz_email_subscription
Data Attributes
data-feedblitz-form
JS Globals
FeedblitzEmailSubscription
Shortcode Output
[feedblitz_email_subscription]
FAQ

Frequently Asked Questions about Subscription Form for Feedblitz