Omnisend for LifterLMS Add-On Security & Risk Analysis

wordpress.org/plugins/omnisend-for-lifterlms-add-on

Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS by Omnisend

0 active installs v1.0.11 PHP 7.4+ WP 4.7.0+ Updated Jan 6, 2026
email-marketingformlifterlmssubscriber-collectionweb-tracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Omnisend for LifterLMS Add-On Safe to Use in 2026?

Generally Safe

Score 100/100

Omnisend for LifterLMS Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The Omnisend for LifterLMS Add-On v1.0.11 exhibits a strong security posture based on the provided static analysis. The absence of any recorded CVEs, including unpatched vulnerabilities, is a significant positive indicator. Furthermore, the code demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and making no external HTTP requests. File operations are also absent, which limits potential file manipulation risks. The high percentage of properly escaped output (89%) is commendable and helps mitigate cross-site scripting (XSS) vulnerabilities.

However, there are some areas that warrant attention. The complete lack of nonce checks and capability checks across all identified entry points is a concern. While the attack surface appears small (0 AJAX handlers, 0 REST API routes, 0 shortcodes, 0 cron events), any future expansion of these entry points without implementing proper authentication and authorization mechanisms would introduce significant risks. The taint analysis shows no issues, but this is based on zero flows analyzed, making it difficult to draw definitive conclusions about the sanitization of data.

In conclusion, the plugin is currently in a good security state, with no known vulnerabilities and generally good coding practices in place. The primary area for improvement is the implementation of robust authentication and authorization checks for any potential future entry points. The lack of taint analysis data is a limitation of the assessment and could be a point of concern if the plugin were to handle more complex data flows.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • Taint analysis data is zero
  • Minor output escaping deficiency (11%)
Vulnerabilities
None known

Omnisend for LifterLMS Add-On Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Omnisend for LifterLMS Add-On Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Omnisend for LifterLMS Add-On Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped37 total outputs
Attack Surface

Omnisend for LifterLMS Add-On Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actionplugins_loadedclass-omnisend-lifterlmsaddon.php:32
actionactivated_pluginclass-omnisend-lifterlmsaddon.php:33
actionadmin_enqueue_scriptsclass-omnisend-lifterlmsaddon.php:34
actionadmin_noticesclass-omnisend-lifterlmsaddon.php:126
actionadmin_noticesclass-omnisend-lifterlmsaddon.php:133
actionadmin_noticesclass-omnisend-lifterlmsaddon.php:140
actionadmin_noticesclass-omnisend-lifterlmsaddon.php:149
actioninitclass-omnisend-lifterlmsaddon.php:152
actionlms_registered_form_actionsclass-omnisend-lifterlmsaddon.php:153
filterllms_get_form_htmlincludes\Service\class-consentservice.php:29
actionlifterlms_user_registeredincludes\Service\class-consentservice.php:32
actionllms_before_user_account_update_submitincludes\Service\class-consentservice.php:33
actionllms_user_enrolled_in_courseincludes\Service\class-consentservice.php:35
actionllms_user_removed_from_courseincludes\Service\class-consentservice.php:36
actionllms_user_added_to_membership_levelincludes\Service\class-consentservice.php:38
actionllms_user_removed_from_membershipincludes\Service\class-consentservice.php:39
actionlifterlms_new_pending_orderincludes\Service\class-consentservice.php:41
actionadmin_menuincludes\Service\class-settingsservice.php:23
actionadmin_initincludes\Service\class-settingsservice.php:24
Maintenance & Trust

Omnisend for LifterLMS Add-On Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 6, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Omnisend for LifterLMS Add-On Developer Profile

Omnisend

9 plugins · 151K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
28 days
View full developer profile
Detection Fingerprints

How We Detect Omnisend for LifterLMS Add-On

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/omnisend-for-lifterlms-add-on/css/omnisend-lifterlms-addon.css
Version Parameters
omnisend-for-lifterlms-add-on/css/omnisend-lifterlms-addon.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Omnisend for LifterLMS Add-On