Formidable Email Shortcodes Security & Risk Analysis

wordpress.org/plugins/formidable-email-shortcodes

Create shortcodes with unique identifiers to use in your Formidable Email Notification Settings. Change email addresses globally from one location.

10 active installs v2.0 PHP + WP 3.5+ Updated Apr 28, 2014
emailformidableformidable-pronotificationsshortcode
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Formidable Email Shortcodes Safe to Use in 2026?

Generally Safe

Score 85/100

Formidable Email Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The formidable-email-shortcodes plugin v2.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by not using dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities. This indicates a generally well-maintained codebase in these areas. However, significant concerns arise from the static analysis. The lack of output escaping on all analyzed outputs is a critical weakness, potentially leading to cross-site scripting (XSS) vulnerabilities. Furthermore, the presence of an unprotected AJAX handler represents a direct attack vector that could be exploited without proper user authentication.

The absence of taint analysis data and the clean vulnerability history are positive indicators, suggesting that past issues have been addressed or have not been prevalent. Nevertheless, the critical findings from the static analysis, particularly the unescaped output and the unprotected AJAX handler, cannot be overlooked. These represent immediate threats that could be leveraged by attackers. While the plugin has a history of being secure, the current version has introduced significant risks that require immediate attention.

Key Concerns

  • Unescaped output on all analyzed outputs
  • AJAX handler without authentication check
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
None known

Formidable Email Shortcodes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Formidable Email Shortcodes Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped12 total outputs
Attack Surface
1 unprotected

Formidable Email Shortcodes Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_ssfes_save_settingsadmin.php:42

Shortcodes 1

[frm_notify] formidable-email-shortcodes.php:53
WordPress Hooks 6
actionadmin_initadmin.php:4
actionadmin_menuadmin.php:7
actionadmin_menuadmin.php:7
actionadmin_enqueue_scriptsadmin.php:24
actionadmin_headadmin.php:25
filterplugin_action_linksformidable-email-shortcodes.php:61
Maintenance & Trust

Formidable Email Shortcodes Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedApr 28, 2014
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Formidable Email Shortcodes Developer Profile

thomstark

5 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Formidable Email Shortcodes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/formidable-email-shortcodes/js/ssfes-admin.js/wp-content/plugins/formidable-email-shortcodes/js/ssfes-alertify.js/wp-content/plugins/formidable-email-shortcodes/css/ssfes-style.css/wp-content/plugins/formidable-email-shortcodes/css/ssfes-alertify.css
Script Paths
/wp-content/plugins/formidable-email-shortcodes/js/ssfes-admin.js/wp-content/plugins/formidable-email-shortcodes/js/ssfes-alertify.js
Version Parameters
formidable-email-shortcodes/js/ssfes-admin.js?ver=formidable-email-shortcodes/js/ssfes-alertify.js?ver=formidable-email-shortcodes/css/ssfes-style.css?ver=formidable-email-shortcodes/css/ssfes-alertify.css?ver=

HTML / DOM Fingerprints

CSS Classes
ssfes-selectItssfes-form-tablessfes-output-tablessfes-oddssfes-even
Data Attributes
id="frm_save_settings"id="frm_instructions"id="frm_support"id="frm_plugins"id="frm_donate"id="ssfes_table"+4 more
JS Globals
ssfes_varsajax_object
Shortcode Output
[frm_notify id=[frm_notify id=
FAQ

Frequently Asked Questions about Formidable Email Shortcodes