
Mail Subscribe List Security & Risk Analysis
wordpress.org/plugins/mail-subscribe-listSimple customizable plugin that displays a name/email form where visitors can submit their information, manageable in the WordPress admin.
Is Mail Subscribe List Safe to Use in 2026?
Use With Caution
Score 55/100Mail Subscribe List has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "mail-subscribe-list" plugin version 2.1.10 exhibits a mixed security posture. On the positive side, the static analysis reveals good coding practices, with a high percentage of SQL queries using prepared statements and output properly escaped. The attack surface is also relatively small and appears to have limited unprotected entry points based on the provided data. Nonce and capability checks are present, which are crucial for securing WordPress functionalities.
However, the plugin's history of known vulnerabilities is a significant concern. The presence of 5 known CVEs, with 1 currently unpatched and categorized as high severity, indicates a recurring pattern of security weaknesses. The historical vulnerability types, including Cross-Site Scripting and Cross-Site Request Forgery, suggest potential issues with how user input is handled and processed, which could be exploited if not thoroughly addressed.
In conclusion, while the current static analysis shows some adherence to security best practices, the plugin's past vulnerability history, particularly the unpatched high-severity issue, poses a substantial risk. Users should be cautious, and immediate attention should be given to addressing the outstanding vulnerability. Further investigation into the root cause of past vulnerabilities is recommended to prevent future occurrences.
Key Concerns
- Unpatched high severity vulnerability
- History of medium severity vulnerabilities
- History of cross-site scripting vulnerabilities
- History of cross-site request forgery vulnerabilities
Mail Subscribe List Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Mail Subscribe List <= 2.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting
Mail Subscribe List <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via smlsubform shortcode
Mail Subscribe List <= 2.1.6 - Stored Cross-Site Scripting
Mail Subscribe List <= 2.1.3 - Cross-Site Request Forgery
Mail Subscribe List <= 2.0.9 - Unauthenticated Stored Cross-Site Scripting
Mail Subscribe List Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Mail Subscribe List Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Mail Subscribe List Maintenance & Trust
Maintenance Signals
Community Trust
Mail Subscribe List Alternatives
Newsletters
newsletters-lite
Newsletter plugin for WordPress to capture subscribers and send beautiful, bulk newsletter emails.
WP PHPList Comment Subscriber
phplist-comment-subscriber
This wordpress plugin gives users the option to subscribe to your PHPList newsletter when adding comments to your blog
CN Blog Mailer
cn-blog-mailer
Simple automated newsletter plugin for WordPress. Automatically email your latest blog posts to subscribers with scheduled newsletters, subscription f …
MailLister
maillister
Mail Lister provide an easy solution to marketing system,
Nord Sub News
nord-sub-news
Simple customizable plugin that displays a name/email form where visitors can submit their information, manageable in the WordPress admin.
Mail Subscribe List Developer Profile
3 plugins · 4K total installs
How We Detect Mail Subscribe List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mail-subscribe-list/sml-subscribe-form.css/wp-content/plugins/mail-subscribe-list/sml-subscribe-form.jsHTML / DOM Fingerprints
sml_subscribesml_hiddenfieldprependsml_thankyousml_namesml_namelabelsml_nameinputsml_email+16 moredata-sml_subscribe_widget_shownamedata-sml_subscribe_widget_nametxtdata-sml_subscribe_widget_nameholderdata-sml_subscribe_widget_emailtxtdata-sml_subscribe_widget_emailholderdata-sml_subscribe_widget_showsubmit+1 morewindow.onload<form class="sml_subscribe"<input class="sml_hiddenfield" name="sml_subscribe"<p class="sml_thankyou"><label class="sml_namelabel"