Plugin Name: FeedBlitz Member Mail Security & Risk Analysis

wordpress.org/plugins/feedblitz-membermail

Build your FeedBlitz email newsletter subscription list faster with simple checkboxes on user registration and / or comment forms.

20 active installs v1.0.1 PHP + WP 2.8.2+ Updated Oct 21, 2012
email-marketingemail-newslettersemail-subscriptionsfeedblitznewsletter
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Plugin Name: FeedBlitz Member Mail Safe to Use in 2026?

Generally Safe

Score 85/100

Plugin Name: FeedBlitz Member Mail has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "feedblitz-membermail" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identifiable attack surface through AJAX handlers, REST API routes, shortcodes, or cron events is a significant strength, indicating that user-facing entry points are minimal or non-existent. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and not performing any file operations or making external HTTP requests that are not explicitly documented as such. Furthermore, the lack of recorded vulnerabilities, including no known CVEs, suggests a history of security diligence from the developers.

However, there are notable areas for concern. The extremely low percentage of properly escaped output (17%) is a critical weakness. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in the context of a user's browser. The complete absence of nonce checks and capability checks, coupled with zero unprotected AJAX handlers or REST API routes, is contradictory. While the analysis states no unprotected entry points, the lack of these fundamental WordPress security mechanisms raises questions about how authorization and integrity are being maintained for any potential internal operations. The lack of any taint analysis flows could be due to a very limited code scope or could indicate an incomplete analysis, leaving potential risks undiscovered.

In conclusion, while the plugin benefits from a clean vulnerability history and good practices in database interaction and attack surface reduction, the severe lack of output escaping and the perplexing absence of core security checks like nonces and capability checks present significant risks. The plugin's security is compromised by the high potential for XSS and an unclear authorization model. The developer should prioritize addressing the output escaping issue and implementing robust authorization checks to mitigate these risks.

Key Concerns

  • Insufficient output escaping
  • Missing nonce checks
  • Missing capability checks
  • No taint analysis reported
Vulnerabilities
None known

Plugin Name: FeedBlitz Member Mail Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Plugin Name: FeedBlitz Member Mail Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

17% escaped6 total outputs
Attack Surface

Plugin Name: FeedBlitz Member Mail Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterplugin_action_linksfeedblitz_membermail.php:58
actionadmin_initfeedblitz_membermail.php:59
actionadmin_menufeedblitz_membermail.php:60
actionregister_formfeedblitz_membermail.php:62
actionregister_postfeedblitz_membermail.php:63
actioncomment_formfeedblitz_membermail.php:64
actionwp_insert_commentfeedblitz_membermail.php:65
Maintenance & Trust

Plugin Name: FeedBlitz Member Mail Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedOct 21, 2012
PHP min version
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Plugin Name: FeedBlitz Member Mail Developer Profile

phollows

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Plugin Name: FeedBlitz Member Mail

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/feedblitz-membermail/css/style.css
Script Paths
/wp-content/plugins/feedblitz-membermail/js/feedblitz_membermail.js
Version Parameters
feedblitz-membermail/css/style.css?ver=feedblitz-membermail/js/feedblitz_membermail.js?ver=

HTML / DOM Fingerprints

Data Attributes
id="feedid"name="feedid"id="fbz_checkbox"name="fbz_checkbox"
JS Globals
abfb_pabfb_cbabfb_text
FAQ

Frequently Asked Questions about Plugin Name: FeedBlitz Member Mail