Formilla Edge Targeted Messaging Platform for Sales and Marketing Security & Risk Analysis

wordpress.org/plugins/formilla-edge

Target customers with the right message at the right time using Formilla Edge email, live chat, and in-app messaging.

30 active installs v1.2 PHP + WP 2.7+ Updated Dec 1, 2025
email-marketingemail-messageemail-newsletteremail-signupmass-mail
100
A · Safe
CVEs total1
Unpatched0
Last CVEApr 21, 2023
Safety Verdict

Is Formilla Edge Targeted Messaging Platform for Sales and Marketing Safe to Use in 2026?

Generally Safe

Score 100/100

Formilla Edge Targeted Messaging Platform for Sales and Marketing has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 21, 2023Updated 4mo ago
Risk Assessment

The "formilla-edge" v1.2 plugin exhibits a generally good security posture based on the static analysis. It has a very small attack surface with only one AJAX handler, and importantly, this entry point appears to have both nonce and capability checks, which is a strong defense against common web attacks. The code also demonstrates responsible SQL practices by exclusively using prepared statements and shows a decent effort in output escaping, with over 70% of outputs being properly handled. There are no identified critical or high severity issues in the taint analysis, and no file operations or external HTTP requests were detected, further reducing potential risk.

However, there are a few areas that warrant attention. The fact that not all output is properly escaped (71%) leaves a potential for Cross-Site Scripting (XSS) vulnerabilities, especially if the unescaped outputs handle user-supplied data. While there are no currently unpatched vulnerabilities, the plugin does have a history of known CVEs, including a medium-severity XSS vulnerability discovered in April 2023. The absence of any unpatched CVEs is positive, but the past occurrence of XSS suggests that careful attention to output sanitization remains crucial. Overall, the plugin is well-implemented with strong foundational security practices, but the small percentage of unescaped output and its past vulnerability history are minor concerns that should be monitored.

Key Concerns

  • Percentage of unescaped output
  • Past medium severity vulnerability
Vulnerabilities
1

Formilla Edge Targeted Messaging Platform for Sales and Marketing Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

WF-59f7a1b2-f718-40e7-8030-b9212edf71b7-formilla-edgemedium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Formilla Edge <= 1.0 - Authenticated (Administrator+) Cross-Site Scripting via 'FormillaPluginID'

Apr 21, 2023 Patched in 1.1 (277d)
Code Analysis
Analyzed Mar 16, 2026

Formilla Edge Targeted Messaging Platform for Sales and Marketing Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
5 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped7 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save_formilla_edge_settings (formilla-edge.php:31)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Formilla Edge Targeted Messaging Platform for Sales and Marketing Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_save_formilla_edge_settingsformilla-edge.php:16
WordPress Hooks 6
actioninitformilla-edge.php:14
actionwp_footerformilla-edge.php:15
filterplugin_action_linksformilla-edge.php:17
filterplugin_row_metaformilla-edge.php:18
actionadmin_menuformilla-edge.php:26
actionadmin_menuformilla-edge.php:27
Maintenance & Trust

Formilla Edge Targeted Messaging Platform for Sales and Marketing Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 1, 2025
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs30
Developer Profile

Formilla Edge Targeted Messaging Platform for Sales and Marketing Developer Profile

zgilyana

2 plugins · 3K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
277 days
View full developer profile
Detection Fingerprints

How We Detect Formilla Edge Targeted Messaging Platform for Sales and Marketing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/formilla-edge/main-logo.png
Script Paths
https://www.formilla.com/scripts/feedback.js

HTML / DOM Fingerprints

CSS Classes
formillaedgeformillawindowholder
Data Attributes
FormillaPluginID
JS Globals
Formillaajaxurl
REST Endpoints
/wp-json/save_formilla_edge_settings
FAQ

Frequently Asked Questions about Formilla Edge Targeted Messaging Platform for Sales and Marketing