
Jellyreach Security & Risk Analysis
wordpress.org/plugins/jellyreachJellyreach is an email and SMS marketing automation tool. This plugin lets WooCommerce stores import data into Jellyreach, and then enables creating s …
Is Jellyreach Safe to Use in 2026?
Generally Safe
Score 85/100Jellyreach has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Jellyreach plugin v1.0.0 exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the adherence to prepared statements for all SQL queries and proper escaping of a majority of outputs are positive indicators of secure coding practices. The plugin also avoids dangerous functions and file operations, which are common sources of vulnerabilities.
However, there are notable concerns. The presence of two taint flows with unsanitized paths, even without critical or high severity, warrants attention as these could potentially lead to unexpected behavior or vulnerabilities if exploited. The lack of nonce and capability checks on any potential entry points, combined with external HTTP requests, suggests potential weaknesses. The vulnerability history being clean is a strength, but it could also indicate that the plugin has not been extensively tested or targeted, rather than being inherently perfect.
In conclusion, while Jellyreach v1.0.0 demonstrates good foundational security practices, the identified taint flows and the absence of authorization checks on potential entry points represent areas for improvement. The clean vulnerability history is positive, but the identified code signals suggest that the plugin is not entirely risk-free and further scrutiny might be beneficial.
Key Concerns
- Taint flows with unsanitized paths detected
- No nonce checks detected
- No capability checks detected
- Some outputs not properly escaped
- External HTTP requests made
Jellyreach Security Vulnerabilities
Jellyreach Code Analysis
Output Escaping
Data Flow Analysis
Jellyreach Attack Surface
WordPress Hooks 11
Maintenance & Trust
Jellyreach Maintenance & Trust
Maintenance Signals
Community Trust
Jellyreach Alternatives
Smart Marketing SMS and Newsletters Forms
smart-marketing-for-wp
E-commerce Automation Engine: Product sync, Track & Engage, and abandoned cart recovery via Email and SMS for WooCommerce stores.
ActiveCampaign – The autonomous marketing platform
activecampaign-subscription-forms
Add ActiveCampaign contact forms and live chat to any post, page, or sidebar. Also enable ActiveCampaign site tracking for your WordPress blog.
Brevo for WooCommerce
woocommerce-sendinblue-newsletter-subscription
All-in-one WooCommerce email marketing, automation, SMS, and CRM by Brevo. Grow your store with powerful marketing tools.
FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce
wp-marketing-automations
Recover lost revenue with Cart Abandonment Recovery for WooCommerce. Increase retention with Post Purchase Follow-Up Emails.
MWB HubSpot for WooCommerce – CRM, Abandoned Cart, Email Marketing, Marketing Automation & Analytics
makewebbetter-hubspot-for-woocommerce
Integrate WooCommerce with HubSpot’s free CRM, abandoned cart tracking, email marketing, marketing automation, analytics & more.
Jellyreach Developer Profile
1 plugin · 30 total installs
How We Detect Jellyreach
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/jellyreach/admin/css/jellyreach-admin.css/wp-content/plugins/jellyreach/admin/js/jellyreach-admin.jsjellyreach-admin.css?ver=jellyreach-admin.js?ver=