Genesis eNews Extended Security & Risk Analysis

wordpress.org/plugins/genesis-enews-extended

Creates a new widget to easily add mailing lists integration to a Genesis website. Works with FeedBurner, MailChimp, AWeber, FeedBlitz, ConvertKit and …

40K active installs v2.2.0 PHP 5.4.0+ WP 4.9.6+ Updated Apr 29, 2025
awebergenesisgenesiswpmailchimpstudiopress
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Genesis eNews Extended Safe to Use in 2026?

Generally Safe

Score 100/100

Genesis eNews Extended has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The plugin "genesis-enews-extended" v2.2.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified attack surface entry points like AJAX handlers, REST API routes, shortcodes, or cron events, especially without authentication checks, is a significant strength. Furthermore, the code demonstrates good practices in preventing common vulnerabilities, with no dangerous functions, zero file operations, and no external HTTP requests. The use of prepared statements for all SQL queries and a high percentage of properly escaped output are commendable. The taint analysis also shows no critical or high severity unsanitized paths, indicating a low risk of code injection or manipulation through tainted data.

However, a notable concern is the complete lack of nonce checks and capability checks. While the current analysis doesn't reveal an immediate exploit due to other protective measures, this absence represents a significant gap in securing potential future or undiscovered entry points. The vulnerability history being entirely clear is a positive indicator, suggesting a generally well-maintained codebase. In conclusion, the plugin is currently very secure, with its strengths heavily outweighing its weaknesses. The primary area for improvement is the implementation of appropriate nonce and capability checks to further harden the plugin against evolving threats.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Genesis eNews Extended Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Genesis eNews Extended Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
183 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped190 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
widget (class-bjgk-genesis-enews-extended.php:81)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Genesis eNews Extended Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioninitplugin.php:36
actionwidgets_initplugin.php:51
Maintenance & Trust

Genesis eNews Extended Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 29, 2025
PHP min version5.4.0
Downloads1.1M

Community Trust

Rating94/100
Number of ratings28
Active installs40K
Developer Profile

Genesis eNews Extended Developer Profile

Brandon Kraft

6 plugins · 41K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Genesis eNews Extended

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/genesis-enews-extended/js/genesis-enews-extended.js/wp-content/plugins/genesis-enews-extended/css/genesis-enews-extended.css
Script Paths
/wp-content/plugins/genesis-enews-extended/js/genesis-enews-extended.js
Version Parameters
genesis-enews-extended/js/genesis-enews-extended.js?ver=genesis-enews-extended/css/genesis-enews-extended.css?ver=

HTML / DOM Fingerprints

CSS Classes
genesis-enews-extended-widget
JS Globals
BJGK_Genesis_ENews_Extended
FAQ

Frequently Asked Questions about Genesis eNews Extended