Omnisend for Paid Memberships Pro Add-On Security & Risk Analysis

wordpress.org/plugins/omnisend-for-paid-memberships-pro-add-on

Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS by Omnisend

0 active installs v1.0.9 PHP 7.4+ WP 4.7.0+ Updated Jan 6, 2026
email-marketingformpaid-memberships-prosubscriber-collectionweb-tracking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Omnisend for Paid Memberships Pro Add-On Safe to Use in 2026?

Generally Safe

Score 100/100

Omnisend for Paid Memberships Pro Add-On has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The Omnisend for Paid Memberships Pro Add-on plugin, version 1.0.9, exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, SQL queries not using prepared statements, file operations, and external HTTP requests are positive indicators. The presence of a nonce check and a high percentage of properly escaped output further contribute to its good security practices.

However, the analysis reveals a concerning lack of explicit capability checks and a complete absence of AJAX handlers, REST API routes, shortcodes, and cron events that are protected by authentication or permission callbacks. While the attack surface appears minimal (zero entry points), this means any potential future additions to these areas would inherently lack protection unless specifically secured. The taint analysis showing zero flows with unsanitized paths is reassuring, but this is in conjunction with zero flows analyzed, which is itself a limitation if the plugin has complex interactions not captured by the analysis.

The plugin's vulnerability history is also a significant strength, with zero known CVEs recorded. This suggests a history of stable and secure development. In conclusion, while the current version appears robust with no immediate critical flaws, the lack of comprehensive authentication checks on potential entry points and the limited scope of the taint analysis present areas for future improvement and ongoing vigilance.

Key Concerns

  • No capability checks found
  • No protected REST API routes
  • No protected AJAX handlers
  • Zero taint flows analyzed
Vulnerabilities
None known

Omnisend for Paid Memberships Pro Add-On Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Omnisend for Paid Memberships Pro Add-On Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
32 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped36 total outputs
Attack Surface

Omnisend for Paid Memberships Pro Add-On Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionplugins_loadedclass-omnisend-paidmembershipsproaddon.php:32
actionactivated_pluginclass-omnisend-paidmembershipsproaddon.php:33
actionadmin_enqueue_scriptsclass-omnisend-paidmembershipsproaddon.php:34
actionadmin_noticesclass-omnisend-paidmembershipsproaddon.php:130
actionadmin_noticesclass-omnisend-paidmembershipsproaddon.php:137
actionadmin_noticesclass-omnisend-paidmembershipsproaddon.php:144
actionadmin_noticesclass-omnisend-paidmembershipsproaddon.php:153
actioninitclass-omnisend-paidmembershipsproaddon.php:156
actionpmp_registered_form_actionsclass-omnisend-paidmembershipsproaddon.php:157
actionpmpro_checkout_after_billing_fieldsincludes\Service\class-consentservice.php:25
actionpmpro_checkout_after_user_fieldsincludes\Service\class-consentservice.php:26
actionpmpro_show_user_profileincludes\Service\class-consentservice.php:27
actionpmpro_after_all_membership_level_changesincludes\Service\class-consentservice.php:28
actionpmpro_after_checkoutincludes\Service\class-consentservice.php:31
actionpmpro_member_profile_edit_form_tagincludes\Service\class-consentservice.php:32
actionadmin_menuincludes\Service\class-settingsservice.php:23
actionadmin_initincludes\Service\class-settingsservice.php:24
Maintenance & Trust

Omnisend for Paid Memberships Pro Add-On Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 6, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Omnisend for Paid Memberships Pro Add-On Developer Profile

Omnisend

9 plugins · 161K total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
42 days
View full developer profile
Detection Fingerprints

How We Detect Omnisend for Paid Memberships Pro Add-On

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/omnisend-for-paid-memberships-pro-add-on/css/omnisend-paid-memberships-pro-addon.css
Version Parameters
omnisend-paid-memberships-pro-addon?ver=omnisend-for-paid-memberships-pro-add-on/class-omnisend-paidmembershipsproaddon.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Omnisend for Paid Memberships Pro Add-On