
Plugin Name: FeedBlitz Member Mail Security & Risk Analysis
wordpress.org/plugins/feedblitz-membermailBuild your FeedBlitz email newsletter subscription list faster with simple checkboxes on user registration and / or comment forms.
Is Plugin Name: FeedBlitz Member Mail Safe to Use in 2026?
Generally Safe
Score 85/100Plugin Name: FeedBlitz Member Mail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "feedblitz-membermail" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identifiable attack surface through AJAX handlers, REST API routes, shortcodes, or cron events is a significant strength, indicating that user-facing entry points are minimal or non-existent. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and not performing any file operations or making external HTTP requests that are not explicitly documented as such. Furthermore, the lack of recorded vulnerabilities, including no known CVEs, suggests a history of security diligence from the developers.
However, there are notable areas for concern. The extremely low percentage of properly escaped output (17%) is a critical weakness. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the context of a user's browser. The complete absence of nonce checks and capability checks, coupled with zero unprotected AJAX handlers or REST API routes, is contradictory. While the analysis states no unprotected entry points, the lack of these fundamental WordPress security mechanisms raises questions about how authorization and integrity are being maintained for any potential internal operations. The lack of any taint analysis flows could be due to a very limited code scope or could indicate an incomplete analysis, leaving potential risks undiscovered.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in database interaction and attack surface reduction, the severe lack of output escaping and the perplexing absence of core security checks like nonces and capability checks present significant risks. The plugin's security is compromised by the high potential for XSS and an unclear authorization model. The developer should prioritize addressing the output escaping issue and implementing robust authorization checks to mitigate these risks.
Key Concerns
- Insufficient output escaping
- Missing nonce checks
- Missing capability checks
- No taint analysis reported
Plugin Name: FeedBlitz Member Mail Security Vulnerabilities
Plugin Name: FeedBlitz Member Mail Code Analysis
Output Escaping
Plugin Name: FeedBlitz Member Mail Attack Surface
WordPress Hooks 7
Maintenance & Trust
Plugin Name: FeedBlitz Member Mail Maintenance & Trust
Maintenance Signals
Community Trust
Plugin Name: FeedBlitz Member Mail Alternatives
Drip for WordPress
email-marketing
Do you sell online? If so you need our new Drip for WooCommerce Plugin instead of this one. It includes your entire product catalog, order history int …
Email Marketing by SendX
email-marketing-by-sendx
SendX is a lead-generation and marketing automation platform to grow your web business. In simple words it is marketing for non-marketers.
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
MailPoet – Newsletters, Email Marketing, and Automation
mailpoet
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & more
Newsletter – Send awesome emails from WordPress
newsletter
An email marketing tool for your blog: subscription forms to create your lists with unlimited subscribers and newsletters.
Plugin Name: FeedBlitz Member Mail Developer Profile
1 plugin · 20 total installs
How We Detect Plugin Name: FeedBlitz Member Mail
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feedblitz-membermail/css/style.css/wp-content/plugins/feedblitz-membermail/js/feedblitz_membermail.jsfeedblitz-membermail/css/style.css?ver=feedblitz-membermail/js/feedblitz_membermail.js?ver=HTML / DOM Fingerprints
id="feedid"name="feedid"id="fbz_checkbox"name="fbz_checkbox"abfb_pabfb_cbabfb_text