
Omnisend for LifterLMS Add-On Security & Risk Analysis
wordpress.org/plugins/omnisend-for-lifterlms-add-onEmail Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS by Omnisend
Is Omnisend for LifterLMS Add-On Safe to Use in 2026?
Generally Safe
Score 100/100Omnisend for LifterLMS Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Omnisend for LifterLMS Add-On v1.0.11 exhibits a strong security posture based on the provided static analysis. The absence of any recorded CVEs, including unpatched vulnerabilities, is a significant positive indicator. Furthermore, the code demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and making no external HTTP requests. File operations are also absent, which limits potential file manipulation risks. The high percentage of properly escaped output (89%) is commendable and helps mitigate cross-site scripting (XSS) vulnerabilities.
However, there are some areas that warrant attention. The complete lack of nonce checks and capability checks across all identified entry points is a concern. While the attack surface appears small (0 AJAX handlers, 0 REST API routes, 0 shortcodes, 0 cron events), any future expansion of these entry points without implementing proper authentication and authorization mechanisms would introduce significant risks. The taint analysis shows no issues, but this is based on zero flows analyzed, making it difficult to draw definitive conclusions about the sanitization of data.
In conclusion, the plugin is currently in a good security state, with no known vulnerabilities and generally good coding practices in place. The primary area for improvement is the implementation of robust authentication and authorization checks for any potential future entry points. The lack of taint analysis data is a limitation of the assessment and could be a point of concern if the plugin were to handle more complex data flows.
Key Concerns
- No nonce checks implemented
- No capability checks implemented
- Taint analysis data is zero
- Minor output escaping deficiency (11%)
Omnisend for LifterLMS Add-On Security Vulnerabilities
Omnisend for LifterLMS Add-On Release Timeline
Omnisend for LifterLMS Add-On Code Analysis
Output Escaping
Omnisend for LifterLMS Add-On Attack Surface
WordPress Hooks 19
Maintenance & Trust
Omnisend for LifterLMS Add-On Maintenance & Trust
Maintenance Signals
Community Trust
Omnisend for LifterLMS Add-On Alternatives
Omnisend for Contact Form 7 Add-On
omnisend-for-contact-form-7
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS by Omnisend
Omnisend for Gravity Forms Add-On
omnisend-for-gravity-forms-add-on
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS by Omnisend
Omnisend for Formidable Forms Add-On
omnisend-for-formidable-forms-add-on
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS by Omnisend
Omnisend for Ninja Forms Add-On
omnisend-for-ninja-forms-add-on
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS by Omnisend
Omnisend for SureCart Add-On
omnisend-for-surecart-add-on
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS by Omnisend
Omnisend for LifterLMS Add-On Developer Profile
9 plugins · 151K total installs
How We Detect Omnisend for LifterLMS Add-On
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/omnisend-for-lifterlms-add-on/css/omnisend-lifterlms-addon.cssomnisend-for-lifterlms-add-on/css/omnisend-lifterlms-addon.css?ver=