
MailPoet Newsletters – Mandrill Spam and Bounce Cleaner Security & Risk Analysis
wordpress.org/plugins/mailpoet-wysija-mandrill-spam-and-bounce-cleanerAllows MailPoet users to easily unsubscribe or delete newsletter subscribers who have bounced, rejected, reported you for spam and more.
Is MailPoet Newsletters – Mandrill Spam and Bounce Cleaner Safe to Use in 2026?
Generally Safe
Score 85/100MailPoet Newsletters – Mandrill Spam and Bounce Cleaner has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "mailpoet-wysija-mandrill-spam-and-bounce-cleaner" v1.0 exhibits a concerning security posture due to a significant number of unprotected entry points. While it demonstrates good practices in database interaction with 100% prepared statements, the lack of authentication checks on all three AJAX handlers represents a critical weakness, potentially allowing unauthorized access to sensitive functionalities. The presence of a dangerous `unserialize` function, coupled with taint analysis revealing two high-severity flows with unsanitized paths, further elevates the risk profile. The low percentage of properly escaped output also indicates a risk of cross-site scripting (XSS) vulnerabilities.
Despite the identified code-level risks, the plugin's vulnerability history is remarkably clean, with zero recorded CVEs. This absence of past vulnerabilities is a positive indicator, suggesting either robust development practices in the past or a lack of historical targeting. However, the current code analysis reveals potential for new vulnerabilities to emerge. The plugin's strengths lie in its secure database queries and a clean vulnerability history. Its weaknesses are concentrated in its attack surface, specifically the unprotected AJAX handlers, the use of `unserialize`, and insufficient output escaping, creating immediate security concerns that should be addressed.
Key Concerns
- 3 unprotected AJAX handlers
- High severity taint flows with unsanitized paths (2)
- Dangerous function: unserialize
- Low percentage of properly escaped output (9%)
- Bundled library: DataTables
MailPoet Newsletters – Mandrill Spam and Bounce Cleaner Security Vulnerabilities
MailPoet Newsletters – Mandrill Spam and Bounce Cleaner Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
MailPoet Newsletters – Mandrill Spam and Bounce Cleaner Attack Surface
AJAX Handlers 3
WordPress Hooks 6
Maintenance & Trust
MailPoet Newsletters – Mandrill Spam and Bounce Cleaner Maintenance & Trust
Maintenance Signals
Community Trust
MailPoet Newsletters – Mandrill Spam and Bounce Cleaner Alternatives
No alternatives data available yet.
MailPoet Newsletters – Mandrill Spam and Bounce Cleaner Developer Profile
1 plugin · 10 total installs
How We Detect MailPoet Newsletters – Mandrill Spam and Bounce Cleaner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mailpoet-wysija-mandrill-spam-and-bounce-cleaner/css/style.css/wp-content/plugins/mailpoet-wysija-mandrill-spam-and-bounce-cleaner/css/jquery-ui.css/wp-content/plugins/mailpoet-wysija-mandrill-spam-and-bounce-cleaner/css/jquery.dataTables.min.css/wp-content/plugins/mailpoet-wysija-mandrill-spam-and-bounce-cleaner/js/jquery.ui.widget.js/wp-content/plugins/mailpoet-wysija-mandrill-spam-and-bounce-cleaner/js/jquery.ui.datepicker.js/wp-content/plugins/mailpoet-wysija-mandrill-spam-and-bounce-cleaner/js/jquery.dataTables.js/wp-content/plugins/mailpoet-wysija-mandrill-spam-and-bounce-cleaner/js/wnc_ajaj.js/wp-content/plugins/mailpoet-wysija-mandrill-spam-and-bounce-cleaner/js/jquery.ui.widget.js/wp-content/plugins/mailpoet-wysija-mandrill-spam-and-bounce-cleaner/js/jquery.ui.datepicker.js/wp-content/plugins/mailpoet-wysija-mandrill-spam-and-bounce-cleaner/js/jquery.dataTables.js/wp-content/plugins/mailpoet-wysija-mandrill-spam-and-bounce-cleaner/js/wnc_ajaj.jsHTML / DOM Fingerprints
ajax_object