
MailPoet Checkout Subscription for WooCommerce (Legacy) Security & Risk Analysis
wordpress.org/plugins/mailpoet-woocommerce-add-onLet your customers subscribe to your newsletters as they checkout with their purchase.
Is MailPoet Checkout Subscription for WooCommerce (Legacy) Safe to Use in 2026?
Generally Safe
Score 85/100MailPoet Checkout Subscription for WooCommerce (Legacy) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of mailpoet-woocommerce-add-on v4.0.1 reveals a generally strong security posture with no identified critical or high-severity vulnerabilities in the code signals or taint analysis. The absence of known CVEs and a clean vulnerability history further bolster this assessment. The plugin demonstrates good practices by implementing nonce checks and capability checks, and by avoiding dangerous functions, file operations, and external HTTP requests. The lack of unprotected entry points in the attack surface is also a significant positive.
However, a notable concern is the presence of SQL queries that are not using prepared statements. With 2 total SQL queries and 0% using prepared statements, this presents a risk of SQL injection, especially if user-supplied data is directly incorporated into these queries. While the taint analysis didn't reveal unsanitized paths leading to critical or high severity issues, the direct use of raw SQL without prepared statements is a fundamental security weakness. Additionally, the output escaping, while at 70% proper, still leaves room for potential cross-site scripting (XSS) vulnerabilities if the unescaped outputs are in sensitive areas.
In conclusion, mailpoet-woocommerce-add-on v4.0.1 shows a solid foundation with no immediate critical threats apparent from the provided data. The historical lack of vulnerabilities is promising. The primary areas for improvement are ensuring all SQL queries utilize prepared statements to mitigate SQL injection risks and enhancing output escaping to prevent XSS. Addressing these specific code-level concerns would significantly strengthen the plugin's overall security.
Key Concerns
- SQL queries not using prepared statements
- Incomplete output escaping (30% not properly escaped)
MailPoet Checkout Subscription for WooCommerce (Legacy) Security Vulnerabilities
MailPoet Checkout Subscription for WooCommerce (Legacy) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
MailPoet Checkout Subscription for WooCommerce (Legacy) Attack Surface
WordPress Hooks 14
Maintenance & Trust
MailPoet Checkout Subscription for WooCommerce (Legacy) Maintenance & Trust
Maintenance Signals
Community Trust
MailPoet Checkout Subscription for WooCommerce (Legacy) Alternatives
MailPoet WP e-Commerce Add-on
mailpoet-wp-e-commerce-add-on
Adds a checkbox on checkout page for your customers to subscribe to your MailPoet newsletters.
Stock Display in Admin Order
stock-display-in-admin-order
Display each product stock numbers, or stock status, directly in the admin order page in Woocommerce.
Klarna for WooCommerce
klarna-payments-for-woocommerce
Grow your business for increased sales and enhanced shopping experiences at no extra costs.
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
Conversion Tracking for WooCommerce
woocommerce-conversion-tracking
Adds various conversion tracking codes to cart, checkout, registration success and product page on WooCommerce
MailPoet Checkout Subscription for WooCommerce (Legacy) Developer Profile
15 plugins · 2K total installs
How We Detect MailPoet Checkout Subscription for WooCommerce (Legacy)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mailpoet-woocommerce-add-on/assets/css/mailpoet-woocommerce-add-on.css/wp-content/plugins/mailpoet-woocommerce-add-on/assets/js/mailpoet-woocommerce-add-on.js/wp-content/plugins/mailpoet-woocommerce-add-on/assets/js/mailpoet-woocommerce-add-on.jsmailpoet-woocommerce-add-on/assets/css/mailpoet-woocommerce-add-on.css?ver=mailpoet-woocommerce-add-on/assets/js/mailpoet-woocommerce-add-on.js?ver=HTML / DOM Fingerprints
mailpoet-woocommerce-add-on-checkout-formmailpoet-woocommerce-add-on-checkboxdata-mailpoet-woocommerce-add-on-form-iddata-mailpoet-woocommerce-add-on-target-list-idmailpoet_woocommerce_add_on_params