
Jellyreach Security & Risk Analysis
wordpress.org/plugins/jellyreachBridge WooCommerce events to Jellyreach — sync orders, carts and customers to power email & SMS marketing automation.
Is Jellyreach Safe to Use in 2026?
Generally Safe
Score 100/100Jellyreach has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Jellyreach plugin v1.0.0 exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the adherence to prepared statements for all SQL queries and proper escaping of a majority of outputs are positive indicators of secure coding practices. The plugin also avoids dangerous functions and file operations, which are common sources of vulnerabilities.
However, there are notable concerns. The presence of two taint flows with unsanitized paths, even without critical or high severity, warrants attention as these could potentially lead to unexpected behavior or vulnerabilities if exploited. The lack of nonce and capability checks on any potential entry points, combined with external HTTP requests, suggests potential weaknesses. The vulnerability history being clean is a strength, but it could also indicate that the plugin has not been extensively tested or targeted, rather than being inherently perfect.
In conclusion, while Jellyreach v1.0.0 demonstrates good foundational security practices, the identified taint flows and the absence of authorization checks on potential entry points represent areas for improvement. The clean vulnerability history is positive, but the identified code signals suggest that the plugin is not entirely risk-free and further scrutiny might be beneficial.
Key Concerns
- Taint flows with unsanitized paths detected
- No nonce checks detected
- No capability checks detected
- Some outputs not properly escaped
- External HTTP requests made
Jellyreach Security Vulnerabilities
Jellyreach Release Timeline
Jellyreach Code Analysis
Output Escaping
Data Flow Analysis
Jellyreach Attack Surface
WordPress Hooks 11
Maintenance & Trust
Jellyreach Maintenance & Trust
Maintenance Signals
Community Trust
Jellyreach Alternatives
Leado Marketing Automation Connector
leado-marketing
Connect WordPress and WooCommerce to Leado Marketing for tracking, popups, forms, web push, contacts, products, and orders.
Brevo for WooCommerce
woocommerce-sendinblue-newsletter-subscription
All-in-one WooCommerce email marketing, automation, SMS, and CRM by Brevo. Grow your store with powerful marketing tools.
MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics
makewebbetter-hubspot-for-woocommerce
Integrate WooCommerce with HubSpot’s free CRM, abandoned cart tracking, email marketing, marketing automation, analytics & more.
Zoho Campaigns
zoho-campaigns
Zoho Campaigns
WP Flashy Marketing Automation
wp-flashy-marketing-automation
Flashy is an all-in-one marketing platform for e-commerce websites to grow sales.
Jellyreach Developer Profile
1 plugin · 30 total installs
How We Detect Jellyreach
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jellyreach/admin/css/jellyreach-admin.css/wp-content/plugins/jellyreach/admin/js/jellyreach-admin.jsjellyreach-admin.css?ver=jellyreach-admin.js?ver=