
Mailer Dragon – Email Marketing Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/mailer-dragonEmail newsletter plugin with autoresponder for effective email marketing in WordPress. Free plugin with unlimited email newsletters & subscribers.
Is Mailer Dragon – Email Marketing Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100Mailer Dragon – Email Marketing Plugin for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Mailer Dragon plugin version 1.1.3 exhibits a generally strong security posture, with no known vulnerabilities and a good adherence to several security best practices. The static analysis reveals a limited attack surface, with all identified entry points (AJAX handlers, shortcodes, cron events) protected by either nonce or capability checks. Furthermore, the absence of critical or high severity taint flows and dangerous functions is a positive indicator.
However, there are some areas for improvement. The plugin utilizes raw SQL queries without prepared statements for all its database interactions. This presents a significant risk, as it makes the plugin vulnerable to SQL injection attacks if user-supplied data is not meticulously sanitized before being included in these queries. The moderate percentage of improperly escaped outputs also suggests a potential for cross-site scripting (XSS) vulnerabilities, though the taint analysis did not reveal any critical or high severity XSS flows. The lack of historical vulnerabilities is encouraging, suggesting a proactive approach to security by the developers, but it does not negate the risks identified in the current code.
Key Concerns
- SQL queries not using prepared statements
- Improper output escaping in 59% of outputs
Mailer Dragon – Email Marketing Plugin for WordPress Security Vulnerabilities
Mailer Dragon – Email Marketing Plugin for WordPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Mailer Dragon – Email Marketing Plugin for WordPress Attack Surface
AJAX Handlers 2
Shortcodes 3
WordPress Hooks 28
Scheduled Events 1
Maintenance & Trust
Mailer Dragon – Email Marketing Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Mailer Dragon – Email Marketing Plugin for WordPress Alternatives
Drip for WordPress
email-marketing
Do you sell online? If so you need our new Drip for WooCommerce Plugin instead of this one. It includes your entire product catalog, order history int …
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
fluent-crm
The easiest and fastest Email Marketing, Newsletter, Marketing Automation Plugin & CRM Solution for WordPress
Kit (formerly ConvertKit) – Email Newsletter, Email Marketing, Membership, Subscribers and Landing Pages
convertkit
Build your email subscriber lists, send email marketing newsletters, sell more products and build your membership site with Kit (formerly ConvertKit).
weMail: Email Marketing, Email Automation, Newsletters, Subscribers & eCommerce Email Optins
wemail
Send email newsletters, automate email marketing with email automation, manage subscribers, eCommerce emails, post notifications & optins with ease
Mailster WordPress Newsletter Plugin
mailster
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & …
Mailer Dragon – Email Marketing Plugin for WordPress Developer Profile
7 plugins · 11K total installs
How We Detect Mailer Dragon – Email Marketing Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mailer-dragon/css/mailer-dragon.min.css/wp-content/plugins/mailer-dragon/js/mailer-dragon-admin.min.js/wp-content/plugins/mailer-dragon/css/mailer-dragon-admin.min.css/wp-content/plugins/mailer-dragon/ext/chosen/chosen.min.css/wp-content/plugins/mailer-dragon/ext/chosen/chosen.jquery.min.js/wp-content/plugins/mailer-dragon/js/mailer-dragon-admin.min.jsmailer-dragon/css/mailer-dragon.min.css?ver=mailer-dragon/js/mailer-dragon-admin.min.js?ver=mailer-dragon/css/mailer-dragon-admin.min.css?ver=mailer-dragon/ext/chosen/chosen.min.css?ver=mailer-dragon/ext/chosen/chosen.jquery.min.js?ver=HTML / DOM Fingerprints
chosen-containerchosen-dropchosen-results<!-- Mailer Dragon Subscribe Form --><!-- Mailer Dragon Thank You --><!-- Mailer Dragon Subscriber IP --><!-- Mailer Dragon - subscribe_form -->+4 moredata-placeholder_option_multipledata-placeholder_valuedata-no_results_textdata-search_containsic_mailer_ajax<p>Your subscr<p>We have received your subscription request, please check your email to confirm.</p><div class="implecode_warning">The URL provided is not correct!</div>