Gist All-In-One Marketing – Live Chat, Popups, Email Security & Risk Analysis

wordpress.org/plugins/marketing-automation-by-convertfox

A free all-in-one marketing plugin that allows you to easily use popups, live chat, site tracking and email marketing on your WordPress site.

600 active installs v2.7 PHP 5.6.20+ WP 5.8+ Updated Aug 17, 2023
emailformsgistlive-chatpopup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gist All-In-One Marketing – Live Chat, Popups, Email Safe to Use in 2026?

Generally Safe

Score 85/100

Gist All-In-One Marketing – Live Chat, Popups, Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The marketing-automation-by-convertfox v2.7 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any identified attack surface points (AJAX, REST API, shortcodes, cron events) is a significant strength, indicating a limited exposure to external manipulation. Furthermore, the plugin demonstrates good practices in data handling with 100% of SQL queries utilizing prepared statements and the complete lack of dangerous functions or file operations. The limited number of capability checks (1) is also a positive sign, suggesting that access control is likely well-defined, although the absence of explicit checks on potential entry points (if they existed) would be a concern.

Despite these strengths, there are areas that warrant caution. The low percentage of properly escaped output (24%) is a notable weakness. This indicates a risk of Cross-Site Scripting (XSS) vulnerabilities, where unsanitized data could be injected into the output and executed by a user's browser. While the taint analysis showed no critical or high severity flows, this is based on a limited number of analyzed flows (0). The vulnerability history being clear of any CVEs is excellent, suggesting a well-maintained and secure codebase historically. However, the lack of historical data also means we cannot assess how the plugin handles past vulnerabilities or its responsiveness to security issues.

In conclusion, the plugin has a strong foundation with a minimal attack surface and secure data handling for SQL. The primary concern lies with the insufficient output escaping, which poses a moderate XSS risk. The absence of identified vulnerabilities is a positive indicator, but the limited scope of the taint analysis and the low output escaping percentage mean vigilance is still advised. Future updates should prioritize addressing the output escaping issues to further solidify its security.

Key Concerns

  • Low output escaping percentage (24%)
Vulnerabilities
None known

Gist All-In-One Marketing – Live Chat, Popups, Email Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gist All-In-One Marketing – Live Chat, Popups, Email Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
5 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

24% escaped21 total outputs
Attack Surface

Gist All-In-One Marketing – Live Chat, Popups, Email Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuconvertfox.php:29
actionadmin_initconvertfox.php:30
actionadmin_enqueue_scriptsconvertfox.php:31
actionwp_headpage.php:2
Maintenance & Trust

Gist All-In-One Marketing – Live Chat, Popups, Email Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedAug 17, 2023
PHP min version5.6.20
Downloads31K

Community Trust

Rating80/100
Number of ratings4
Active installs600
Developer Profile

Gist All-In-One Marketing – Live Chat, Popups, Email Developer Profile

Gist

2 plugins · 610 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gist All-In-One Marketing – Live Chat, Popups, Email

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/marketing-automation-by-convertfox/script.js

HTML / DOM Fingerprints

Data Attributes
name='convertfox_settings[is_enabled]'name='convertfox_settings[identify_users]'name='convertfox_settings[identity_verify_users]'name='convertfox_settings[identity_secret_key]'name='convertfox_settings[disable_for_admin]'name='convertfox_settings[messenger_visibility_front_page]'+6 more
FAQ

Frequently Asked Questions about Gist All-In-One Marketing – Live Chat, Popups, Email