
Mailgun Subscriptions Security & Risk Analysis
wordpress.org/plugins/mailgun-subscriptionsAdd a Mailgun subscription form to your WordPress site. Your visitors can use the form to subscribe to your lists using the Mailgun API.
Is Mailgun Subscriptions Safe to Use in 2026?
Generally Safe
Score 99/100Mailgun Subscriptions has a strong security track record. Known vulnerabilities have been patched promptly.
The mailgun-subscriptions v1.3.3 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and avoids dangerous functions and file operations. The absence of critical or high-severity taint analysis findings is also a positive indicator. However, there are notable areas of concern. The plugin has two AJAX handlers, and critically, both lack authentication checks, presenting a significant attack surface for unauthorized actions. While nonce checks are present, their effectiveness is diminished when the handlers themselves are not protected by capability checks.
The vulnerability history shows a single medium-severity Cross-Site Scripting (XSS) vulnerability in the past, which is currently patched. This suggests that while past vulnerabilities have been addressed, the potential for input sanitization issues exists. The fact that this was a medium-severity XSS highlights the importance of thorough output escaping, and while the plugin has a high percentage of properly escaped outputs, the 41% that are not properly escaped could still be a vector for vulnerabilities if untrusted input reaches these points.
In conclusion, the plugin has strengths in its database interaction and avoidance of certain risky operations. However, the unprotected AJAX endpoints are a major weakness that could be exploited by attackers. The past XSS vulnerability, even though patched, serves as a reminder to remain vigilant about output escaping and input sanitization for all entry points. The overall risk is moderate, primarily driven by the unauthenticated AJAX handlers.
Key Concerns
- Unprotected AJAX handlers
- Insufficient output escaping
- Past medium severity XSS vulnerability
Mailgun Subscriptions Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mailgun Subscriptions <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Mailgun Subscriptions Code Analysis
SQL Query Safety
Output Escaping
Mailgun Subscriptions Attack Surface
AJAX Handlers 2
Shortcodes 3
WordPress Hooks 22
Maintenance & Trust
Mailgun Subscriptions Maintenance & Trust
Maintenance Signals
Community Trust
Mailgun Subscriptions Alternatives
Mailjet Email Marketing
mailjet-for-wordpress
Includes WooCommerce automated and order emails. Design, send and track engaging marketing and transactional emails from your WordPress admin.
Email Subscription Popup
email-subscribe
This plugin shows you a beautiful newsletter subscription popup when someone enter to your site. You can even use widget that allow email subscription …
Contact Form Widget
new-contact-form-widget
Create contact forms with query table management. Simple setup, secure submissions, and easy customization for your site.
Newsletter Subscription Form – User Subscriptions Form, Capture Email
newsletter-subscription-form
Newsletter Subscription Form for WordPress is the ultimate lead generation, customer acquisition and email marketing plugin to grow and engage your ma …
Mailchimp Widget by ProteusThemes
proteusthemes-mailchimp-widget
Capture your visitor's email address and subscribe them to your newsletter campaign with this simple Mailchimp widget plugin!
Mailgun Subscriptions Developer Profile
6 plugins · 1K total installs
How We Detect Mailgun Subscriptions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mailgun-subscriptions/assets/mailgun-subscriptions.css/wp-content/plugins/mailgun-subscriptions/assets/mailgun-subscriptions.js/wp-content/plugins/mailgun-subscriptions/assets/mailgun-subscriptions.jsmailgun-subscriptions/assets/mailgun-subscriptions.css?ver=mailgun-subscriptions/assets/mailgun-subscriptions.js?ver=HTML / DOM Fingerprints
mailgun-subscriptions-widgetmailgun-subscriptions-formdata-mailgun-subscriptions-ajaxurlMailgunSubscriptions[mailgun_subscribe_form][mailgun_subscribe_button][mailgun_unsubscribe_form][mailgun_account_page]