Movylo Marketing Automation Security & Risk Analysis

wordpress.org/plugins/movylo-widget

Build your Customer List by capturing leads from your website and social and then automatically convert the list into real sales.

700 active installs v2.0.7 PHP 7.4+ WP 5.5+ Updated Oct 29, 2024
capture-leadsmonetizemovylowidget
70
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 14, 2025
Download
Safety Verdict

Is Movylo Marketing Automation Safe to Use in 2026?

Mostly Safe

Score 70/100

Movylo Marketing Automation is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 14, 2025Updated 1yr ago
Risk Assessment

The 'movylo-widget' v2.0.7 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and incorporating a decent number of nonce and capability checks. The static analysis shows no critical or high severity taint flows, and the attack surface appears small with no directly exposed entry points found.

However, several concerns warrant attention. The presence of unsanitized paths in two taint flows, while not rated critical or high, indicates a potential for path traversal or file manipulation vulnerabilities if these flows are triggered by user input. Furthermore, the plugin has a history of known vulnerabilities, including a recently discovered medium-severity Cross-Site Scripting (XSS) issue that remains unpatched. The output escaping is also a concern, with 38% of outputs not being properly escaped, which is a common vector for XSS attacks.

In conclusion, while 'movylo-widget' has some strong security foundations, the unpatched XSS vulnerability and the identified unsanitized path flows represent significant risks. The incomplete output escaping further exacerbates these potential weaknesses. Prioritizing the patching of the known CVE and thoroughly investigating the unsanitized path flows should be the immediate focus for improving the plugin's security.

Key Concerns

  • Unpatched CVE (Medium severity XSS)
  • Flows with unsanitized paths (2)
  • Output escaping (38% not properly escaped)
Vulnerabilities
1

Movylo Marketing Automation Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32608medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Movylo Marketing Automation <= 2.0.7 - Reflected Cross-Site Scripting

Apr 14, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Movylo Marketing Automation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
13 escaped
Nonce Checks
4
Capability Checks
0
File Operations
2
External Requests
3
Bundled Libraries
0

Output Escaping

62% escaped21 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
do_action_and_print_setting_page (includes\movylo-main.php:51)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Movylo Marketing Automation Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuincludes\movylo-main.php:16
actionadmin_enqueue_scriptsincludes\movylo-main.php:17
actionwp_headincludes\movylo-main.php:18
Maintenance & Trust

Movylo Marketing Automation Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedOct 29, 2024
PHP min version7.4
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs700
Developer Profile

Movylo Marketing Automation Developer Profile

Movylo

1 plugin · 700 total installs

73
trust score
Avg Security Score
70/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Movylo Marketing Automation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/movylo-widget/css/admin.css

HTML / DOM Fingerprints

CSS Classes
shortcuts-managerswk_admin_cardswk_admin_bodysection-titlefield
Data Attributes
id="accountCreation"id="accountCreationForm"id="accountConnection"id="accountConnectionForm"name="movylo_create_account"name="movylo_api_id"+2 more
FAQ

Frequently Asked Questions about Movylo Marketing Automation