MP Automate Lite for MailPoet Security & Risk Analysis

wordpress.org/plugins/mp-automate-lite-for-mailpoet

Manage your subscribers automatically between your Mailpoet mailinglists

20 active installs v1.0.0 PHP 7.0+ WP 4.6+ Updated Mar 13, 2021
automate-subscriber-managementautomationmailpoetmanage-subscribers-automaticallymultiple-lists
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is MP Automate Lite for MailPoet Safe to Use in 2026?

Generally Safe

Score 85/100

MP Automate Lite for MailPoet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "mp-automate-lite-for-mailpoet" v1.0.0 plugin exhibits a concerning security posture despite its lack of recorded vulnerabilities. The static analysis reveals a significant attack surface with three AJAX handlers, all of which lack authentication checks. This means any unauthenticated user could potentially interact with these handlers, leading to unintended actions or information disclosure. While the plugin uses prepared statements for all its SQL queries, which is a strong security practice, the lack of proper output escaping on 69% of its outputs is a major concern. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not properly sanitized before being displayed back to the user. The absence of nonces and capability checks on the AJAX endpoints further exacerbates the risk of unauthorized actions. Given the limited code signals for dangerous functions and the clean vulnerability history, the plugin might be relatively simple, but these fundamental security oversights present a clear and present danger.

Key Concerns

  • AJAX handlers without auth checks
  • Significant unescaped output
  • Missing nonce checks on AJAX
  • Missing capability checks on AJAX
Vulnerabilities
None known

MP Automate Lite for MailPoet Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MP Automate Lite for MailPoet Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
18
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
9
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

31% escaped26 total outputs
Attack Surface
3 unprotected

MP Automate Lite for MailPoet Attack Surface

Entry Points3
Unprotected3

AJAX Handlers 3

authwp_ajax_save_mpa_lite_rulesincludes\class-mpa-lite-handler.php:36
authwp_ajax_save_mpa_lite_log_settingsincludes\class-mpa-lite-handler.php:37
authwp_ajax_reset_mpa_lite_logincludes\class-mpa-lite-handler.php:38
WordPress Hooks 10
actionadmin_menuincludes\class-mpa-lite-handler.php:32
actionadmin_enqueue_scriptsincludes\class-mpa-lite-handler.php:33
actionmpa_settings_tabincludes\class-mpa-lite-handler.php:34
actionmpa_settings_tab_contentincludes\class-mpa-lite-handler.php:35
actionmpa_lite_daily_workerincludes\mpa-lite-scheduler.php:21
actionmpa_lite_monthly_workerincludes\mpa-lite-scheduler.php:42
filtercron_schedulesincludes\mpa-lite-scheduler.php:55
actionplugins_loadedmp-automate-lite.php:29
actionadmin_noticesmp-automate-lite.php:58
actionadmin_noticesmp-automate-lite.php:71

Scheduled Events 2

mpa_lite_daily_worker
mpa_lite_monthly_worker
Maintenance & Trust

MP Automate Lite for MailPoet Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 13, 2021
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

MP Automate Lite for MailPoet Developer Profile

Lucy Eind

3 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MP Automate Lite for MailPoet

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mp-automate-lite-for-mailpoet/assets/css/mp-automate-lite.css
Script Paths
/wp-content/plugins/mp-automate-lite-for-mailpoet/assets/js/mp-automate-lite.js
Version Parameters
mp-automate-lite/style.css?ver=mp-automate-lite.css?ver=mp-automate-lite.js?ver=

HTML / DOM Fingerprints

CSS Classes
mpa-lite-settingsmpa-lite-logmpa-lite-upgrade
Data Attributes
data-tab-content
JS Globals
mpa_lite_vars
FAQ

Frequently Asked Questions about MP Automate Lite for MailPoet