
MailPoet bbPress Add-on Security & Risk Analysis
wordpress.org/plugins/mailpoet-bbpress-add-onEnables your new forum members to subscribe to a newsletter while registering on the forum. Requires the use of [bbp-register] shortcode.
Is MailPoet bbPress Add-on Safe to Use in 2026?
Generally Safe
Score 85/100MailPoet bbPress Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'mailpoet-bbpress-add-on' v1.0.0 plugin demonstrates a generally good security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs, critical taint flows, dangerous functions, or unprotected entry points is a strong positive indicator. The plugin also appears to have a limited attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited without proper checks.
However, there are a few areas of concern that warrant attention. The single SQL query identified is not using prepared statements, which poses a risk of SQL injection if the data used in the query is not properly sanitized. While the plugin has capability checks, the absence of nonce checks on potential entry points (even though none are explicitly listed) could be a vulnerability if new entry points are introduced or if the current ones are not adequately secured against CSRF attacks. The output escaping, while at 78%, still leaves room for improvement and could lead to cross-site scripting (XSS) vulnerabilities in the remaining 22% of outputs.
Given the clean vulnerability history, it's reasonable to assume that the developers have a focus on security. However, the identified SQL query issue and the potential for unescaped outputs represent tangible risks. The plugin's strength lies in its minimal attack surface and lack of historical vulnerabilities, but the presence of a non-prepared SQL query and a slight weakness in output escaping means it's not entirely risk-free.
Key Concerns
- Raw SQL query without prepared statements
- Output escaping not 100% proper
- Missing nonce checks on potential entry points
MailPoet bbPress Add-on Security Vulnerabilities
MailPoet bbPress Add-on Code Analysis
SQL Query Safety
Output Escaping
MailPoet bbPress Add-on Attack Surface
WordPress Hooks 21
Maintenance & Trust
MailPoet bbPress Add-on Maintenance & Trust
Maintenance Signals
Community Trust
MailPoet bbPress Add-on Alternatives
MailPoet Gravity Forms Add-on
mailpoet-gravity-forms-add-on
Adds a new field for you to allow your visitors to subscriber to your MailPoet newsletters.
MailPoet WP e-Commerce Add-on
mailpoet-wp-e-commerce-add-on
Adds a checkbox on checkout page for your customers to subscribe to your MailPoet newsletters.
Add-on WooCommerce – MailPoet 3
add-on-woocommerce-mailpoet
Let your customers subscribe to your MailPoet 3 newsletter as they checkout from WooCommerce with their purchase.
MailPoet Checkout Subscription for WooCommerce (Legacy)
mailpoet-woocommerce-add-on
Let your customers subscribe to your newsletters as they checkout with their purchase.
Ninja Forms – MailPoet
ninja-forms-mailpoet
This extension integrates Ninja Forms with MailPoet by providing an option to add users who submit a form to an existing newsletter.
MailPoet bbPress Add-on Developer Profile
15 plugins · 2K total installs
How We Detect MailPoet bbPress Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mailpoet-bbpress-add-on/css//wp-content/plugins/mailpoet-bbpress-add-on/js//wp-content/plugins/mailpoet-bbpress-add-on/js/frontend.jsmailpoet-bbpress-add-on/css/frontend.css?ver=mailpoet-bbpress-add-on/js/frontend.js?ver=HTML / DOM Fingerprints
MAILPOET_BBPRESS_ADDON