WP Marketing Security & Risk Analysis

wordpress.org/plugins/intellasphere

Fastest way to integrate WP Marketing widgets on a website, such as contact us, offers, events, promoter sign-ups, polls,surveys, feedback, newsletter …

0 active installs v1.1.7 PHP 5.2.4+ WP 4.9+ Updated Unknown
eventslead-generationoffersreviewswp-marketing
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Marketing Safe to Use in 2026?

Generally Safe

Score 100/100

WP Marketing has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The intellasphere v1.1.7 plugin exhibits a mixed security posture. While it demonstrates good practices in output escaping (92% properly escaped) and largely uses prepared statements for SQL queries (78%), several significant concerns exist. The most alarming finding is the large number of unprotected entry points, with 14 out of 14 AJAX handlers and 1 out of 1 REST API routes lacking authentication or capability checks. This creates a substantial attack surface accessible to unauthenticated users.

Taint analysis reveals 6 total flows, with all 6 having unsanitized paths and 2 identified as high severity. This, combined with the lack of authentication on many entry points, suggests a high risk of injection vulnerabilities or data manipulation. The absence of any recorded vulnerability history is a positive sign, indicating a potentially stable codebase, but it does not negate the immediate risks identified in the static and taint analyses. The plugin has strengths in its output escaping and SQL query handling, but the critical lack of access control on numerous entry points and high-severity taint flows represent significant weaknesses that must be addressed.

Key Concerns

  • 14 AJAX handlers without auth checks
  • 1 REST API route without permission callback
  • 2 high severity taint flows with unsanitized paths
  • 6 total taint flows with unsanitized paths
  • Only 2 nonce checks for 14 AJAX handlers
  • Only 1 capability check for 15 unprotected entry points
Vulnerabilities
None known

WP Marketing Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Marketing Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

WP Marketing Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
7 prepared
Unescaped Output
208
2483 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
13
Bundled Libraries
0

SQL Query Safety

78% prepared9 total queries

Output Escaping

92% escaped2691 total outputs
Data Flows · Security
6 unsanitized

Data Flow Analysis

6 flows6 with unsanitized paths
get_calender_events (class.itsp-utility.php:643)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
15 unprotected

WP Marketing Attack Surface

Entry Points16
Unprotected15

AJAX Handlers 14

authwp_ajax_process_reservationclass.itsp-scripts.php:19
noprivwp_ajax_process_reservationclass.itsp-scripts.php:20
authwp_ajax_process_the_ajaxclass.itsp-scripts.php:21
noprivwp_ajax_process_the_ajaxclass.itsp-scripts.php:22
authwp_ajax_select_engageclass.itsp-scripts.php:24
authwp_ajax_get_calender_eventsclass.itsp-scripts.php:25
noprivwp_ajax_get_calender_eventsclass.itsp-scripts.php:26
authwp_ajax_process_to_connectclass.itsp-scripts.php:28
authwp_ajax_banner_tableclass.itsp-scripts.php:29
authwp_ajax_select_engageclass.itsp-utility.php:23
authwp_ajax_get_calender_eventsclass.itsp-utility.php:24
noprivwp_ajax_get_calender_eventsclass.itsp-utility.php:25
authwp_ajax_process_to_connectclass.itsp-utility.php:26
authwp_ajax_banner_tableclass.itsp-utility.php:27

REST API Routes 1

GET/wp-json/api/v1/engage/(?P<id>[a-z0-9\-_]+)class.itsp-gutenberg.php:42

Shortcodes 1

[itsp_bannerlist] functions.php:50
WordPress Hooks 24
filterninja_forms_register_actionsaddons-integration.php:15
actiongform_loadedaddons-integration.php:43
actionadmin_menuadmin\class.itsp.settings.php:28
actionadmin_post_is_save_optionsadmin\class.itsp.settings.php:29
actioninitadmin\class.itsp.settings.php:177
actioninitclass.itsp-gutenberg.php:12
actionrest_api_initclass.itsp-gutenberg.php:13
filterblock_categories_allclass.itsp-gutenberg.php:14
actionwp_enqueue_scriptsclass.itsp-scripts.php:17
actionenqueue_block_editor_assetsclass.itsp-scripts.php:18
actionwp_print_scriptsclass.itsp-scripts.php:23
actionadmin_enqueue_scriptsclass.itsp-scripts.php:27
actionwp_enqueue_scriptsclass.itsp-utility.php:20
actionenqueue_block_editor_assetsclass.itsp-utility.php:21
actionadmin_enqueue_scriptsclass.itsp-utility.php:22
actionwidgets_initclass.itsp-widgets-gutenberg.php:24
actioninitfunctions.php:107
actionhttp_api_curlfunctions.php:121
actionwp_headfunctions.php:259
actionwp_footerfunctions.php:264
filterengage_filterfunctions.php:269
actionwp_headfunctions.php:288
actionfl_builder_ui_enqueue_scriptsintellasphere.php:423
actionadmin_footer-widgets.phpwidgets\class-itsp-engage.php:23
Maintenance & Trust

WP Marketing Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version5.2.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

WP Marketing Developer Profile

Sivaprasad Masina

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Marketing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/intellasphere/assets/css/style.css/wp-content/plugins/intellasphere/assets/css/admin/style.css/wp-content/plugins/intellasphere/admin/js/settings.js/wp-content/plugins/intellasphere/admin/js/script.js/wp-content/plugins/intellasphere/assets/js/frontend.js
Script Paths
/wp-content/plugins/intellasphere/admin/js/settings.js/wp-content/plugins/intellasphere/admin/js/script.js/wp-content/plugins/intellasphere/assets/js/frontend.js
Version Parameters
intellasphere/assets/css/style.css?ver=intellasphere/assets/css/admin/style.css?ver=intellasphere/admin/js/settings.js?ver=intellasphere/admin/js/script.js?ver=intellasphere/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Intellasphere modules & includes --><!-- Intellasphere modules & includes -->
JS Globals
window.ITSP_INTELLASPHERE_VERSIONwindow.ITSP_INTEGRATION__PLUGIN_DIRwindow.ITSP_HTTPSwindow.ITSP_INTEGRATION__PLUGIN_URLwindow.ITSP_MILLISECONDSwindow.ITSP_NAME+11 more
REST Endpoints
/wp-json/intellasphere/v1/
FAQ

Frequently Asked Questions about WP Marketing