Moosend Website Connector Security & Risk Analysis

wordpress.org/plugins/moosend-email-marketing

Improve your conversion rates with cart abandonment and product recommendations emails with a click of a button. Track website behaviour of all visito …

1K active installs v1.0.190 PHP + WP 4.1+ Updated Sep 28, 2024
cart-abandonmentecommerceemail-marketingmarketingmulti-channel-marketing
92
A · Safe
CVEs total1
Unpatched0
Last CVEDec 8, 2022
Safety Verdict

Is Moosend Website Connector Safe to Use in 2026?

Generally Safe

Score 92/100

Moosend Website Connector has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 8, 2022Updated 1yr ago
Risk Assessment

The "moosend-email-marketing" plugin v1.0.190 exhibits a generally good security posture based on the static analysis. The absence of any detected dangerous functions, raw SQL queries, or file operations is a strong indicator of secure coding practices. Furthermore, all detected output is properly escaped, and the plugin utilizes prepared statements for its SQL queries, which significantly mitigates the risk of SQL injection vulnerabilities. The presence of nonce and capability checks, even with a limited attack surface, is also a positive sign.

Key Concerns

  • Plugin has 1 known CVE
  • Bundled library Guzzle detected
Vulnerabilities
1

Moosend Website Connector Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

Moosend Website Connector <= 1.0.189 - Missing Authorization

Dec 8, 2022 Patched in 1.0.190 (411d)
Code Analysis
Analyzed Mar 16, 2026

Moosend Website Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
18 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

100% escaped18 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
renderSettingsPage (MooTracker.php:260)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Moosend Website Connector Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionwpMooTracker.php:30
actionwoocommerce_add_to_cartMooTracker.php:31
actionwoocommerce_checkout_order_processedMooTracker.php:32
actionwoocommerce_payment_completeMooTracker.php:33
actionadmin_menuMooTracker.php:34
actionadmin_noticesMooTracker.php:35
filterplugin_action_links_moosend-email-marketing/index.phpMooTracker.php:36
actionwp_print_scriptsMooTracker.php:39
actionwp_footerMooTracker.php:126
actionwp_footerMooTracker.php:164
actionwp_footerMooTracker.php:231
actionwp_footerMooTracker.php:245
Maintenance & Trust

Moosend Website Connector Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 28, 2024
PHP min version
Downloads30K

Community Trust

Rating60/100
Number of ratings4
Active installs1K
Developer Profile

Moosend Website Connector Developer Profile

moosend

1 plugin · 1K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
411 days
View full developer profile
Detection Fingerprints

How We Detect Moosend Website Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/moosend-email-marketing/assets/css/tracking.css/wp-content/plugins/moosend-email-marketing/assets/js/admin-tracking.js/wp-content/plugins/moosend-email-marketing/assets/js/admin.js
Script Paths
//cdn.stat-track.com/statics/moosend-tracking.min.js
Version Parameters
moosend-email-marketing/assets/css/tracking.css?ver=moosend-email-marketing/assets/js/admin-tracking.js?ver=moosend-email-marketing/assets/js/admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Moosend Tracking and Forms library -->
Data Attributes
data-moosend-email-field
JS Globals
mootrack
FAQ

Frequently Asked Questions about Moosend Website Connector