
Pigeon Pack Security & Risk Analysis
wordpress.org/plugins/pigeon-packFree and easy email marketing, newsletters, and campaigns; built into your WordPress dashboard!
Is Pigeon Pack Safe to Use in 2026?
Generally Safe
Score 85/100Pigeon Pack has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pigeon-pack" v1.3.0 plugin demonstrates a generally good security posture with a well-defined attack surface and strong adherence to WordPress security best practices in several areas. The complete absence of known CVEs and unpatched vulnerabilities in its history is a significant positive, suggesting a history of responsible development and maintenance.
However, the static analysis reveals some areas of concern. The presence of the `unserialize` function, while only one instance, is a known risky function that can lead to deserialization vulnerabilities if not handled with extreme care and robust input validation. Furthermore, a substantial 86% of output operations are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis also highlights 6 high-severity flows with unsanitized paths, which directly correlate with potential vulnerabilities, likely XSS or other injection attacks due to the unescaped output.
While the plugin boasts no unpatched vulnerabilities, which is commendable, the static analysis points to inherent risks within the current codebase that could manifest as new vulnerabilities if not addressed. The strengths lie in its minimal attack surface with all entry points seemingly protected and the consistent use of prepared statements for SQL queries. However, the significant number of unescaped outputs and the high-severity taint flows are critical weaknesses that require immediate attention to mitigate the risk of exploitation.
Key Concerns
- High percentage of unsanitized output flows
- Dangerous function 'unserialize' found
- High number of taint flows with unsanitized paths
- Low percentage of properly escaped outputs
Pigeon Pack Security Vulnerabilities
Pigeon Pack Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Pigeon Pack Attack Surface
AJAX Handlers 6
Shortcodes 2
WordPress Hooks 32
Scheduled Events 5
Maintenance & Trust
Pigeon Pack Maintenance & Trust
Maintenance Signals
Community Trust
Pigeon Pack Alternatives
Drip for WordPress
email-marketing
Do you sell online? If so you need our new Drip for WooCommerce Plugin instead of this one. It includes your entire product catalog, order history int …
Benchmark Email Lite
benchmark-email-lite
Your Wordpress Site and Email Marketing all in one place!
Newsletter Subscription Form – User Subscriptions Form, Capture Email
newsletter-subscription-form
Newsletter Subscription Form for WordPress is the ultimate lead generation, customer acquisition and email marketing plugin to grow and engage your ma …
Email Subscribers – Group Selector
email-subscribers-advanced-form
Add-on for Email Subscribers plugin using which you can provide option to your users to select interested groups in the Subscribe Form.
Contact Form 7 – Campaign Monitor Addon
contact-form-7-campaignmonitor-addon
Add the capability to create newsletter opt-in forms with Contact Form 7. Automatically submit subscribers to predetermined lists in Campaign Monitor.
Pigeon Pack Developer Profile
5 plugins · 270 total installs
How We Detect Pigeon Pack
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pigeon-pack/css/pigeonpack-admin.css/wp-content/plugins/pigeon-pack/css/pigeonpack.css/wp-content/plugins/pigeon-pack/js/pigeonpack-admin.js/wp-content/plugins/pigeon-pack/js/pigeonpack.js/wp-content/plugins/pigeon-pack/js/pigeonpack-admin-shortcodes.js/wp-content/plugins/pigeon-pack/images/pigeon-16x16.png/wp-content/plugins/pigeon-pack/js/pigeonpack-admin.js/wp-content/plugins/pigeon-pack/js/pigeonpack.js/wp-content/plugins/pigeon-pack/js/pigeonpack-admin-shortcodes.jspigeon-pack/css/pigeonpack-admin.css?ver=pigeon-pack/css/pigeonpack.css?ver=pigeon-pack/js/pigeonpack-admin.js?ver=pigeon-pack/js/pigeonpack.js?ver=pigeon-pack/js/pigeonpack-admin-shortcodes.js?ver=HTML / DOM Fingerprints
pigeonpack-admin-form-fieldpigeonpack-label<!-- Premium Plugin Filters --><!-- Main PHP file used to for initial calls to Pigeon Pack classes and functions. --><!-- ATTENTION: This is *only* done during plugin activation hook in this example! --><!-- You should *NEVER EVER* do this on every page load!! -->+4 moredata-pigeonpack-noncepigeonpackPIGEON_PACK_AJAX_URL[pigeon_pack_subscribe_form][pigeon_pack_subscribe_form][pigeon_pack_subscribe_form][pigeon_pack_subscribe_form]