
Let Them Unsubscribe Security & Risk Analysis
wordpress.org/plugins/let-them-unsubscribeLet users delete their accounts from Wordpress Admin Panel
Is Let Them Unsubscribe Safe to Use in 2026?
Generally Safe
Score 85/100Let Them Unsubscribe has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "let-them-unsubscribe" plugin v1.2.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface, with no apparent unprotected entry points. Furthermore, the code demonstrates good practices by exclusively using prepared statements for all SQL queries and implementing nonce and capability checks. The lack of file operations and external HTTP requests further reduces potential exposure. However, a notable concern is the moderate rate of unescaped output (only 43% properly escaped), which could lead to Cross-Site Scripting (XSS) vulnerabilities if untrusted data is ever introduced into these output contexts, despite the absence of identified taint flows in this specific analysis. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a history of secure development or a lack of historical exploitation. Overall, the plugin is well-secured with limited attack vectors and good fundamental security practices, but the output escaping rate warrants attention for potential XSS risks.
Key Concerns
- Low percentage of properly escaped output
Let Them Unsubscribe Security Vulnerabilities
Let Them Unsubscribe Code Analysis
Output Escaping
Let Them Unsubscribe Attack Surface
WordPress Hooks 8
Maintenance & Trust
Let Them Unsubscribe Maintenance & Trust
Maintenance Signals
Community Trust
Let Them Unsubscribe Alternatives
User Role Switcher
wp-user-role-switcher
Instant switching between user roles in WordPress.
BP Edit User Profiles
bp-edit-user-profiles
Adds a "Edit BuddyPress Profile" link to the users page in the dashboard if current user is an administrator.
UM User Switching
um-user-switching
Addon that integrates User Switching to Ultimate Member
WP Mechanic
wp-mechanic
WP Mechanic is a combination of WordPress and Android Playstore Applications. Experience a set of hybrid software applications.
User Switching
user-switching
Instant switching between user accounts in WordPress and WooCommerce.
Let Them Unsubscribe Developer Profile
4 plugins · 170 total installs
How We Detect Let Them Unsubscribe
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/let-them-unsubscribe/inc/helpers.php/wp-content/plugins/let-them-unsubscribe/admin/settings-menu.php/wp-content/plugins/let-them-unsubscribe/admin/user-profile.php/wp-content/plugins/let-them-unsubscribe/inc/widget.php/wp-content/plugins/let-them-unsubscribe/inc/upgrade.php/wp-content/plugins/let-them-unsubscribe/admin/unsubscribe-menu.php/wp-content/plugins/let-them-unsubscribe/admin-page.phpHTML / DOM Fingerprints
iw_ltu