MailingBoss WP Plugin Security & Risk Analysis

wordpress.org/plugins/mailingboss

Official MailingBoss WP Plugin.

700 active installs v1.0.18 PHP + WP 5.0+ Updated Dec 14, 2023
builderallemailmailingbossnewslettersubscribe
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is MailingBoss WP Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

MailingBoss WP Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The static analysis of MailingBoss v1.0.18 reveals a generally robust security posture. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface. Furthermore, the code demonstrates strong adherence to secure coding practices with no dangerous functions, zero external HTTP requests, and all SQL queries utilizing prepared statements. The absence of known vulnerabilities and CVEs in its history is also a positive indicator. However, a significant concern arises from the output escaping, where only 46% of outputs are properly escaped. This leaves a considerable portion of the plugin's output potentially vulnerable to cross-site scripting (XSS) attacks, especially given the lack of explicit capability checks for entry points, though the overall entry point count is zero. The taint analysis showing zero flows is promising but could be incomplete if the analysis itself had limitations. In conclusion, while MailingBoss v1.0.18 exhibits strengths in preventing common web vulnerabilities like SQL injection and limiting its attack surface, the low percentage of properly escaped output presents a notable risk that warrants attention and remediation.

Key Concerns

  • Low percentage of properly escaped output
  • Absence of capability checks for entry points
Vulnerabilities
None known

MailingBoss WP Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MailingBoss WP Plugin Release Timeline

v1.0.19
v1.0.18Current
v1.0.17
v1.0.16
v1.0.15
v1.0.14
v1.0.13
v1.0.12
v1.0.11
v1.0.10
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

MailingBoss WP Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

46% escaped46 total outputs
Attack Surface

MailingBoss WP Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedincludes\class-mailingboss-wp-plugin.php:118
actionadmin_enqueue_scriptsincludes\class-mailingboss-wp-plugin.php:132
actionadmin_enqueue_scriptsincludes\class-mailingboss-wp-plugin.php:133
actionadmin_menuincludes\class-mailingboss-wp-plugin.php:134
actioninitincludes\class-mailingboss-wp-plugin.php:135
actionadmin_noticesincludes\class-mailingboss-wp-plugin.php:136
actionwp_enqueue_scriptsincludes\class-mailingboss-wp-plugin.php:156
actionwp_enqueue_scriptsincludes\class-mailingboss-wp-plugin.php:157
actionwidgets_initincludes\widgets\class-mailingboss-wp-plugin-form-widget.php:47
Maintenance & Trust

MailingBoss WP Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedDec 14, 2023
PHP min version
Downloads27K

Community Trust

Rating20/100
Number of ratings1
Active installs700
Developer Profile

MailingBoss WP Plugin Developer Profile

Builderall

2 plugins · 2K total installs

77
trust score
Avg Security Score
67/100
Avg Patch Time
6 days
View full developer profile
Detection Fingerprints

How We Detect MailingBoss WP Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mailingboss-wp-plugin/css/mailingboss-wp-plugin-admin.css/wp-content/plugins/mailingboss-wp-plugin/js/mailingboss-wp-plugin-admin.js/wp-content/plugins/mailingboss-wp-plugin/js/mailingboss-wp-plugin-block.js
Script Paths
/wp-content/plugins/mailingboss-wp-plugin/js/mailingboss-wp-plugin-admin.js/wp-content/plugins/mailingboss-wp-plugin/js/mailingboss-wp-plugin-block.js
Version Parameters
mailingboss-wp-plugin-admin.css?ver=mailingboss-wp-plugin-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
mailingboss-wp-plugin-form-block
Data Attributes
data-mbwp-form
JS Globals
mbwp_form_list
Shortcode Output
[mailingboss_form
FAQ

Frequently Asked Questions about MailingBoss WP Plugin