MailUp for WordPress – Email and Newsletter Subscription Form Security & Risk Analysis

wordpress.org/plugins/mailup-email-and-newsletter-subscription-form

Il plugin permette di inserire sul proprio sito WordPress un form per l’iscrizione degli utenti a newsletter, campagne email e SMS.

2K active installs v1.2.7 PHP 7.2+ WP 5.7.2+ Updated May 22, 2025
e-mail-marketingemail-marketingemail-signupnewsletter-marketingnewsletter-sending
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MailUp for WordPress – Email and Newsletter Subscription Form Safe to Use in 2026?

Generally Safe

Score 100/100

MailUp for WordPress – Email and Newsletter Subscription Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The mailup-email-and-newsletter-subscription-form plugin version 1.2.7 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no known vulnerabilities or CVEs recorded, suggesting a history of responsible development. However, the static analysis reveals significant security concerns. A notable issue is the presence of four AJAX handlers that lack authentication checks, presenting a substantial attack surface for unauthorized actions. Furthermore, the plugin has a very low rate of proper output escaping (11%), indicating a high risk of cross-site scripting (XSS) vulnerabilities, especially when combined with the unprotected AJAX endpoints.

The lack of taint analysis results is neutral, but the identified code signals are worrying. The absence of nonce checks on the AJAX handlers amplifies the risk of CSRF attacks. While there are no dangerous functions or file operations flagged, and external HTTP requests are limited, the combination of unprotected entry points and inadequate output sanitization creates a precarious security situation. The plugin's strengths lie in its SQL query handling and lack of historical vulnerabilities, but these are overshadowed by the immediate risks posed by unprotected AJAX endpoints and potential XSS flaws due to insufficient output escaping.

Key Concerns

  • AJAX handlers without authentication
  • Low percentage of properly escaped output
  • AJAX handlers without nonce checks
Vulnerabilities
None known

MailUp for WordPress – Email and Newsletter Subscription Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MailUp for WordPress – Email and Newsletter Subscription Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
34
4 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

11% escaped38 total outputs
Attack Surface
4 unprotected

MailUp for WordPress – Email and Newsletter Subscription Form Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_save_formsincludes\class-mailup.php:207
authwp_ajax_autocomplete_groupincludes\class-mailup.php:208
authwp_ajax_mupwp_save_contactincludes\class-mailup.php:228
noprivwp_ajax_mupwp_save_contactincludes\class-mailup.php:229
WordPress Hooks 11
actionplugins_loadedincludes\class-mailup.php:191
actionadmin_menuincludes\class-mailup.php:204
actionadmin_enqueue_scriptsincludes\class-mailup.php:205
actionadmin_enqueue_scriptsincludes\class-mailup.php:206
actionadmin_headincludes\class-mailup.php:209
actionwidgets_initincludes\class-mailup.php:210
actionwp_before_admin_bar_renderincludes\class-mailup.php:211
actionplugins_loadedincludes\class-mailup.php:212
actionwp_enqueue_scriptsincludes\class-mailup.php:226
actionwp_enqueue_scriptsincludes\class-mailup.php:227
actioninitincludes\class-mailup.php:230
Maintenance & Trust

MailUp for WordPress – Email and Newsletter Subscription Form Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 22, 2025
PHP min version7.2
Downloads17K

Community Trust

Rating54/100
Number of ratings3
Active installs2K
Developer Profile

MailUp for WordPress – Email and Newsletter Subscription Form Developer Profile

MailUp

1 plugin · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MailUp for WordPress – Email and Newsletter Subscription Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mailup-email-and-newsletter-subscription-form/css/mailup-admin.css/wp-content/plugins/mailup-email-and-newsletter-subscription-form/js/jquery.validate.min.js/wp-content/plugins/mailup-email-and-newsletter-subscription-form/js/mailup-admin.js
Script Paths
/wp-content/plugins/mailup-email-and-newsletter-subscription-form/js/jquery.validate.min.js/wp-content/plugins/mailup-email-and-newsletter-subscription-form/js/mailup-admin.js
Version Parameters
/wp-content/plugins/mailup-email-and-newsletter-subscription-form/css/mailup-admin.css?ver=/wp-content/plugins/mailup-email-and-newsletter-subscription-form/js/jquery.validate.min.js?ver=/wp-content/plugins/mailup-email-and-newsletter-subscription-form/js/mailup-admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Currently plugin version. --><!-- Start at version 1.2.7 --><!-- The code that runs during plugin activation. --><!-- The code that runs during plugin deactivation. -->+22 more
Data Attributes
data-wp-binddata-type
JS Globals
mailup_params
REST Endpoints
/wp-json/mailup/v1
FAQ

Frequently Asked Questions about MailUp for WordPress – Email and Newsletter Subscription Form