EO4WP: EmailOctopus for WordPress Security & Risk Analysis

wordpress.org/plugins/fw-integration-for-emailoctopus

Increase the subscribers for your website by using EmailOctopus and this professional integration plugin for WordPress, Elementor and WooCommerce.

100 active installs v1.0.11.2 PHP 7.4+ WP 6.0+ Updated Oct 30, 2025
elementoremailoctopusform-actionsintegrationwoocommerce
99
A · Safe
CVEs total2
Unpatched0
Last CVEMar 27, 2025
Safety Verdict

Is EO4WP: EmailOctopus for WordPress Safe to Use in 2026?

Generally Safe

Score 99/100

EO4WP: EmailOctopus for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Mar 27, 2025Updated 5mo ago
Risk Assessment

The "fw-integration-for-emailoctopus" plugin version 1.0.11.2 exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices in several areas. Notably, 100% of SQL queries utilize prepared statements, and an impressive 96% of output is properly escaped, significantly reducing the risk of SQL injection and Cross-Site Scripting (XSS) vulnerabilities originating from direct output manipulation. The plugin also has a relatively small attack surface with no exposed REST API routes and a minimal number of AJAX handlers and shortcodes, all of which appear to have authorization checks, which is a good security measure. There are no detected dangerous functions or file operations, further bolstering its security. However, the presence of two medium severity CVEs in its history, specifically related to XSS, despite none being currently unpatched, suggests a pattern of past vulnerabilities that require ongoing vigilance. The taint analysis showing two flows with unsanitized paths, even without critical or high severity, warrants attention as these could potentially lead to issues if not handled carefully in future updates. The external HTTP requests, while not inherently a risk, are an area to monitor for potential supply chain attacks or communication with compromised third-party services.

Key Concerns

  • Medium severity CVEs in history
  • Taint flows with unsanitized paths
  • External HTTP requests
Vulnerabilities
2

EO4WP: EmailOctopus for WordPress Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-30763medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

EO4WP <= 1.0.8.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 27, 2025 Patched in 1.0.8.5 (7d)
CVE-2025-22327medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

EO4WP <= 1.0.8.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 3, 2025 Patched in 1.0.8.2 (40d)
Code Analysis
Analyzed Mar 16, 2026

EO4WP: EmailOctopus for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
77 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

96% escaped80 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
subform_action_callback (fw-integration-for-emailoctopus.php:291)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

EO4WP: EmailOctopus for WordPress Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_emailoctopus_subscribeform_actionfw-integration-for-emailoctopus.php:79
noprivwp_ajax_emailoctopus_subscribeform_actionfw-integration-for-emailoctopus.php:80

Shortcodes 1

[FWEO_EmailOctopusSubForm] include\form-shortcodes.php:17
WordPress Hooks 12
actionelementor_pro/initform-actions\emailoctopus.php:274
actionadmin_noticesfw-integration-for-emailoctopus.php:58
actionplugins_loadedfw-integration-for-emailoctopus.php:66
actionwp_enqueue_scriptsfw-integration-for-emailoctopus.php:74
actionadmin_enqueue_scriptsfw-integration-for-emailoctopus.php:75
actionelementor_pro/forms/actions/registerfw-integration-for-emailoctopus.php:89
actionwoocommerce_order_status_changedinclude\class-woo-emailoctopus-integration.php:26
actionadmin_initinclude\options.php:23
actionadmin_initinclude\options.php:24
actionadmin_menuinclude\options.php:25
filterwoocommerce_integrationswoo-emailoctopus-integration.php:37
actionwoocommerce_checkout_update_order_metawoo-emailoctopus-integration.php:43
Maintenance & Trust

EO4WP: EmailOctopus for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedOct 30, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

EO4WP: EmailOctopus for WordPress Developer Profile

Olaf Lederer

2 plugins · 120 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
39 days
View full developer profile
Detection Fingerprints

How We Detect EO4WP: EmailOctopus for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fw-integration-for-emailoctopus/assets/adminstyle.css/wp-content/plugins/fw-integration-for-emailoctopus/assets/admin.js/wp-content/plugins/fw-integration-for-emailoctopus/include/emailoctopus.js/wp-content/plugins/fw-integration-for-emailoctopus/include/style.css
Script Paths
/wp-content/plugins/fw-integration-for-emailoctopus/include/emailoctopus.js/wp-content/plugins/fw-integration-for-emailoctopus/assets/admin.js
Version Parameters
fw-integration-for-emailoctopus/assets/adminstyle.css?ver=fw-integration-for-emailoctopus/assets/admin.js?ver=fw-integration-for-emailoctopus/include/emailoctopus.js?ver=fw-integration-for-emailoctopus/include/style.css?ver=fw-integration-for-emailoctopus/woo-emailoctopus-integration.php?ver=

HTML / DOM Fingerprints

CSS Classes
dashicons-edit
Data Attributes
data-listiddata-redirectdata-success-messagedata-error-messagedata-fields
JS Globals
eo_ajax_objectFWEO_EmailOctopus_integration
Shortcode Output
[FWEO_EmailOctopusSubForm]
FAQ

Frequently Asked Questions about EO4WP: EmailOctopus for WordPress