Mailster Live Security & Risk Analysis

wordpress.org/plugins/mailster-live

See who opens your newsletter campaigns in real time.

600 active installs v2.0.0 PHP + WP 6.0+ Updated May 27, 2024
analyticsemailmailsternewslettertracking
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mailster Live Safe to Use in 2026?

Generally Safe

Score 92/100

Mailster Live has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'mailster-live' v2.0.0 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests, coupled with the use of prepared statements for all SQL queries and proper output escaping for the majority of outputs, are strong indicators of secure coding practices. The presence of nonce and capability checks, while only one each, suggests an awareness of WordPress security mechanisms.

However, a significant concern arises from the plugin's attack surface. It exposes one AJAX handler that lacks any authentication checks. This unprotected entry point represents a potential avenue for attackers to exploit, even if the internal logic of the handler is robust. The lack of taint analysis results, while potentially indicating no identified issues, could also mean that the analysis was not performed or comprehensive enough to detect certain types of vulnerabilities. The plugin's vulnerability history is clean, which is a positive sign, suggesting a history of secure development. Overall, while the code shows good fundamental security practices, the single unprotected AJAX endpoint is a notable weakness that requires attention.

The plugin demonstrates strengths in its disciplined use of prepared statements and output escaping, as well as the absence of common risky functionalities. The primary weakness lies in the unprotected AJAX handler, which is a clear security risk. The clean vulnerability history is reassuring, but it's important to maintain vigilance, especially given the identified unprotected entry point. Addressing this specific concern would significantly improve the plugin's overall security.

Key Concerns

  • Unprotected AJAX handler
  • Minor output escaping issues
Vulnerabilities
None known

Mailster Live Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mailster Live Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
15 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped18 total outputs
Attack Surface
1 unprotected

Mailster Live Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_mailster_live_checkclasses\live.class.php:51
WordPress Hooks 8
actionplugins_loadedclasses\live.class.php:21
filtermailster_capabilitiesclasses\live.class.php:22
actionadmin_noticesclasses\live.class.php:31
actionload-newsletter_page_mailster_dashboardclasses\live.class.php:41
actionadd_meta_boxesclasses\live.class.php:42
actionadmin_enqueue_scriptsclasses\live.class.php:43
filtermailster_setting_sectionsclasses\live.class.php:46
actionmailster_section_tab_liveclasses\live.class.php:47
Maintenance & Trust

Mailster Live Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 27, 2024
PHP min version
Downloads17K

Community Trust

Rating60/100
Number of ratings1
Active installs600
Developer Profile

Mailster Live Developer Profile

EverPress

28 plugins · 121K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
255 days
View full developer profile
Detection Fingerprints

How We Detect Mailster Live

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mailster-live/assets/css/style.css/wp-content/plugins/mailster-live/assets/js/script.js
Script Paths
/wp-content/plugins/mailster-live/assets/js/script.js
Version Parameters
mailster-live/assets/js/script.js?ver=mailster-live/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
mailster-live-dashboard
Data Attributes
data-pauseonblurdata-maptypedata-mapzoomdata-maplatdata-maplng
JS Globals
mailsterlive
FAQ

Frequently Asked Questions about Mailster Live