iConvert Email Marketer Security & Risk Analysis

wordpress.org/plugins/iconvert-email-marketer

iConvert Email Marketer

10 active installs v1.0.3 PHP 7.4+ WP 6.5+ Updated Dec 19, 2025
emailgmailnewslettersendgridsmtp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is iConvert Email Marketer Safe to Use in 2026?

Generally Safe

Score 100/100

iConvert Email Marketer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The static analysis of iConvert Email Marketer v1.0.3 presents a generally positive security posture with no immediately obvious critical vulnerabilities. The plugin demonstrates good practices by utilizing prepared statements for all SQL queries and performing output escaping on a high percentage of outputs. The absence of known CVEs and a clean vulnerability history further bolster this positive outlook. The plugin also includes capability checks for some operations, which is a good security measure.

However, there are some areas for concern that warrant attention. The complete lack of AJAX handlers, REST API routes, shortcodes, and cron events, while contributing to a zero attack surface from these entry points, could also indicate a very limited functionality or a plugin that relies entirely on other mechanisms for its operations, which isn't explicitly detailed in the provided data. The presence of Lodash, while a common library, could pose a risk if it's an outdated version and an exploit exists for it. Furthermore, the absence of nonce checks is a notable omission, especially if the plugin were to introduce any AJAX or form submissions in the future, as this leaves potential openings for CSRF attacks. The taint analysis showing zero flows, while good, might be due to the limited scope of the analysis or the plugin's simplicity.

In conclusion, iConvert Email Marketer v1.0.3 appears to be developed with security in mind, particularly regarding data integrity through prepared statements and output sanitization. The lack of historical vulnerabilities is a strong indicator of consistent security. Nevertheless, the absence of nonce checks and the potential risk associated with bundled libraries, coupled with a somewhat opaque attack surface due to its apparent simplicity, suggest that vigilance is still required. Further investigation into the plugin's specific functionalities and dependencies would be beneficial for a comprehensive security assessment.

Key Concerns

  • Missing nonce checks
  • Bundled Lodash library
Vulnerabilities
None known

iConvert Email Marketer Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

iConvert Email Marketer Release Timeline

v1.0.3Current
Code Analysis
Analyzed Apr 16, 2026

iConvert Email Marketer Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
15 escaped
Nonce Checks
0
Capability Checks
5
File Operations
2
External Requests
0
Bundled Libraries
1

Bundled Libraries

Lodash

Output Escaping

88% escaped17 total outputs
Attack Surface

iConvert Email Marketer Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionadmin_enqueue_scriptsApp/Core/Admin/Actions/Assets.php:17
actionrest_api_initApp/Core/Admin/Actions/EditorActions.php:6
filtericonvertem_parse_contentApp/Core/Admin/Actions/EmailTemplateTags.php:13
actioninitApp/Core/Blocks/BlockRegistry.php:7
actioninitApp/Core/Structure/EmailTemplateCPT.php:37
actionrest_api_initApp/Core/Structure/EmailTemplateCPT.php:40
actioninitApp/Core/Structure/EmailTemplateCPT.php:41
filteruser_can_richeditApp/Core/Structure/EmailTemplateCPT.php:453
filteruse_block_editor_for_postApp/Core/Structure/EmailTemplateCPT.php:466
filterwp_editor_expandApp/Core/Structure/EmailTemplateCPT.php:479
actionedit_form_after_titleApp/Core/Structure/EmailTemplateCPT.php:493
actionadmin_footerApp/Core/Structure/EmailTemplateCPT.php:500
filtertemplate_includeApp/Core/Structure/EmailTemplatePreview.php:6
actionrest_api_initApp/Core/Structure/SendingOptions.php:19
actionphpmailer_initApp/Core/Structure/SendingOptions.php:21
filterwp_mail_fromApp/Core/Structure/SendingOptions.php:24
filterwp_mail_from_nameApp/Core/Structure/SendingOptions.php:25
actionadmin_enqueue_scriptsApp/Core/Structure/SendingOptions.php:27
actionwp_mail_failedApp/Core/Structure/SendingOptions.php:247
Maintenance & Trust

iConvert Email Marketer Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 19, 2025
PHP min version7.4
Downloads185

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

iConvert Email Marketer Developer Profile

Extend Themes

60 plugins · 430K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
127 days
View full developer profile
Detection Fingerprints

How We Detect iConvert Email Marketer

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/iconvert-email-marketer/build/admin/edit-mail/index.js/wp-content/plugins/iconvert-email-marketer/build/admin/edit-mail/style-index.css
Script Paths
/wp-content/plugins/iconvert-email-marketer/build/admin/edit-mail/index.js
Version Parameters
iconvert-email-marketer/build/admin/edit-mail/style-index.css?ver=

HTML / DOM Fingerprints

Data Attributes
data-iconvertem-richtext
JS Globals
window.iconvertemRichText
REST Endpoints
/wp/v2/types?context=view/wp/v2/taxonomies?context=view/wp/v2/block-patterns?context=edit/wp/v2/icem-mail-tpl?context=edit/wp/v2/types/icem-mail-tpl?context=edit/wp/v2/users/me/wp/v2/attachments?context=edit/wp/v2/pages?context=edit/wp/v2/block-exists?context=edit/wp/v2/icem-mail-tpl/autosaves?context=edit/wp/v2/settings
FAQ

Frequently Asked Questions about iConvert Email Marketer