
Formidable Email Shortcodes Security & Risk Analysis
wordpress.org/plugins/formidable-email-shortcodesCreate shortcodes with unique identifiers to use in your Formidable Email Notification Settings. Change email addresses globally from one location.
Is Formidable Email Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100Formidable Email Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The formidable-email-shortcodes plugin v2.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by not using dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities. This indicates a generally well-maintained codebase in these areas. However, significant concerns arise from the static analysis. The lack of output escaping on all analyzed outputs is a critical weakness, potentially leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the presence of an unprotected AJAX handler represents a direct attack vector that could be exploited without proper user authentication.
The absence of taint analysis data and the clean vulnerability history are positive indicators, suggesting that past issues have been addressed or have not been prevalent. Nevertheless, the critical findings from the static analysis, particularly the unescaped output and the unprotected AJAX handler, cannot be overlooked. These represent immediate threats that could be leveraged by attackers. While the plugin has a history of being secure, the current version has introduced significant risks that require immediate attention.
Key Concerns
- Unescaped output on all analyzed outputs
- AJAX handler without authentication check
- Lack of nonce checks
- Lack of capability checks
Formidable Email Shortcodes Security Vulnerabilities
Formidable Email Shortcodes Code Analysis
Output Escaping
Formidable Email Shortcodes Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Formidable Email Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
Formidable Email Shortcodes Alternatives
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
email-subscribers
Add subscription forms on the website and send newsletters & automatically send post notification about new blog posts once it gets published.
ActiveCampaign Postmark for WordPress
postmark-approved-wordpress-plugin
The officially-supported ActiveCampaign Postmark plugin for Wordpress.
Disable Theme and Plugin Auto-Update Emails
disable-theme-and-plugin-auto-update-emails
Disables the default notification emails sent by a site after an automatic theme and/or plugin update. Simply activate the plugin to disable these ema …
miniOrange OTP Login, Verification and SMS Notifications
miniorange-otp-verification
OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification
Disable New User Notification Emails
disable-new-user-notifications
This plugin does one thing - disables user registration notification emails.
Formidable Email Shortcodes Developer Profile
5 plugins · 130 total installs
How We Detect Formidable Email Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formidable-email-shortcodes/js/ssfes-admin.js/wp-content/plugins/formidable-email-shortcodes/js/ssfes-alertify.js/wp-content/plugins/formidable-email-shortcodes/css/ssfes-style.css/wp-content/plugins/formidable-email-shortcodes/css/ssfes-alertify.css/wp-content/plugins/formidable-email-shortcodes/js/ssfes-admin.js/wp-content/plugins/formidable-email-shortcodes/js/ssfes-alertify.jsformidable-email-shortcodes/js/ssfes-admin.js?ver=formidable-email-shortcodes/js/ssfes-alertify.js?ver=formidable-email-shortcodes/css/ssfes-style.css?ver=formidable-email-shortcodes/css/ssfes-alertify.css?ver=HTML / DOM Fingerprints
ssfes-selectItssfes-form-tablessfes-output-tablessfes-oddssfes-evenid="frm_save_settings"id="frm_instructions"id="frm_support"id="frm_plugins"id="frm_donate"id="ssfes_table"+4 moressfes_varsajax_object[frm_notify id=[frm_notify id=