
Promotator Security & Risk Analysis
wordpress.org/plugins/promotatorThis plugin is meant to simplify your daily email marketing life, with it's global sending abilities!
Is Promotator Safe to Use in 2026?
Generally Safe
Score 85/100Promotator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Promotator plugin v1.1 exhibits significant security concerns, primarily due to its unprotected entry points. With two AJAX handlers lacking any authentication or capability checks, these present a substantial attack surface for unauthorized actions. While the plugin avoids dangerous functions and utilizes prepared statements for its SQL queries, its output escaping is only 20% properly implemented, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. The presence of unsanitized paths in taint analysis further reinforces these concerns, indicating potential for path traversal or file manipulation vulnerabilities. The absence of any recorded vulnerability history might suggest a lack of past exploitation or reporting, but it does not negate the risks identified in the static analysis. Overall, the plugin's strengths in SQL handling are overshadowed by critical weaknesses in access control and output sanitation.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
- Taint flows with unsanitized paths
- No nonce checks on entry points
- No capability checks on entry points
Promotator Security Vulnerabilities
Promotator Release Timeline
Promotator Code Analysis
Output Escaping
Data Flow Analysis
Promotator Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Promotator Maintenance & Trust
Maintenance Signals
Community Trust
Promotator Alternatives
Acumbamail
acumbamail-signup-forms
Show your Acumbamail signup forms easily in your Wordpress pages through a widget.
Benchmark Email Lite
benchmark-email-lite
Your Wordpress Site and Email Marketing all in one place!
Email Marketing Plugin – WP Email Capture
wp-email-capture
Double opt-in form for building your email list. Define landing pages to distribute your ebooks & software.
Mailster Gravity Forms
mailster-gravity-forms
Integrates Mailster Newsletter Plugin with Gravity Forms to subscribe users with a Gravity Form.
Get a Newsletter
getanewsletter
Turn visitors into subscribers. Eliminate manual entry of subscribers with signup forms that sync directly with your Get a Newsletter account.
Promotator Developer Profile
10 plugins · 220 total installs
How We Detect Promotator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/promotator/assets/admin.css/wp-content/plugins/promotator/assets/admin.js/wp-content/plugins/promotator/assets/admin.jspromotator/assets/admin.css?ver=promotator/assets/admin.js?ver=HTML / DOM Fingerprints
<!-- post-container --><!-- /post-container -->[link][featured-src][title][text]