MailUp Auto Subscription Security & Risk Analysis

wordpress.org/plugins/mailup-auto-subscribtion

Let users subscribe to MailUp newsletter service in the same time they're registering to your site.

60 active installs v1.2.0 PHP + WP 4.0+ Updated Jun 13, 2025
groupsmailupnewslettersubscription
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 27, 2025
Safety Verdict

Is MailUp Auto Subscription Safe to Use in 2026?

Generally Safe

Score 99/100

MailUp Auto Subscription has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 27, 2025Updated 9mo ago
Risk Assessment

The mailup-auto-subscribtion plugin, version 1.2.0, exhibits a generally good security posture with no identified critical or high-severity issues during static analysis and taint flows. The absence of dangerous functions, SQL injection vulnerabilities due to prepared statements, and a lack of file operations are positive indicators. Furthermore, the plugin demonstrates good practices by implementing nonce checks and capability checks on some of its entry points. However, the plugin does make external HTTP requests, which can introduce risks if not handled securely, and only half of its output is properly escaped, leaving potential for cross-site scripting (XSS) vulnerabilities.

The vulnerability history shows one previously disclosed medium-severity CVE, which has since been patched. This past vulnerability was a CSRF, indicating a potential pattern of such issues. While there are no currently unpatched vulnerabilities, the past occurrence suggests a need for continued vigilance regarding CSRF prevention. The overall security is decent due to the lack of critical code-level flaws, but the unescaped output and external requests are areas that warrant attention for further hardening.

Key Concerns

  • Half of output is not properly escaped
  • Makes external HTTP requests
  • One past medium vulnerability (CSRF)
Vulnerabilities
1

MailUp Auto Subscription Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-13521medium · 6.1Cross-Site Request Forgery (CSRF)

MailUp Auto Subscription <= 1.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Jan 27, 2025 Patched in 1.2.0 (1d)
Code Analysis
Analyzed Mar 16, 2026

MailUp Auto Subscription Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
13 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

50% escaped26 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
mas_options (mailup-auto-subscription.php:67)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MailUp Auto Subscription Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionregister_formincludes\mas-register-form.php:27
actionplugins_loadedmailup-auto-subscription.php:26
actionadmin_menumailup-auto-subscription.php:37
actionadmin_enqueue_scriptsmailup-auto-subscription.php:60
actionuser_registermailup-auto-subscription.php:190
Maintenance & Trust

MailUp Auto Subscription Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 13, 2025
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

MailUp Auto Subscription Developer Profile

ilGhera

13 plugins · 2K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
129 days
View full developer profile
Detection Fingerprints

How We Detect MailUp Auto Subscription

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mailup-auto-subscribtion/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.css/wp-content/plugins/mailup-auto-subscribtion/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.js/wp-content/plugins/mailup-auto-subscribtion/js/tzCheckbox/js/script.js
Version Parameters
mailup-auto-subscribtion/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.css?ver=mailup-auto-subscribtion/js/tzCheckbox/jquery.tzCheckbox/jquery.tzCheckbox.js?ver=mailup-auto-subscribtion/js/tzCheckbox/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wrap-leftwrap-right
Data Attributes
mas-mailup-registration-noncemas-admin-options-nonce
FAQ

Frequently Asked Questions about MailUp Auto Subscription