
Simple JWT Login MailPoet – Login users from newsletter Security & Risk Analysis
wordpress.org/plugins/simple-jwt-login-mailpoetThe Simple JWT Login MailPoet plugin is an add-on for the Simple-Jwt-Login plugin.
Is Simple JWT Login MailPoet – Login users from newsletter Safe to Use in 2026?
Generally Safe
Score 100/100Simple JWT Login MailPoet – Login users from newsletter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-jwt-login-mailpoet" v1.0.2 plugin presents a mixed security posture. On the positive side, the static analysis indicates a lack of identified attack surface points (AJAX, REST API, shortcodes, cron), no dangerous functions, and all SQL queries utilizing prepared statements. The vulnerability history is also clean, with no recorded CVEs, suggesting a stable and potentially well-maintained codebase in terms of known external threats. However, a significant concern arises from the output escaping. With 24 total outputs and 0% properly escaped, this opens the door to potential Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is not correctly sanitized before being displayed to users could be exploited by attackers. The absence of nonce checks and capability checks on entry points, although the entry points themselves are reported as zero, is a point of caution. If any new entry points were to be introduced or if the initial analysis missed something, this could lead to significant security risks. The lack of taint analysis results is also noteworthy; it's unclear if this is because no flows were analyzed or if no potentially malicious flows were detected. Overall, while the plugin shows good practices in terms of SQL and a clean vulnerability history, the critical lack of output escaping is a substantial weakness that requires immediate attention.
Key Concerns
- 0% of outputs properly escaped
- No nonce checks present
- No capability checks present
Simple JWT Login MailPoet – Login users from newsletter Security Vulnerabilities
Simple JWT Login MailPoet – Login users from newsletter Release Timeline
Simple JWT Login MailPoet – Login users from newsletter Code Analysis
Output Escaping
Simple JWT Login MailPoet – Login users from newsletter Attack Surface
WordPress Hooks 4
Maintenance & Trust
Simple JWT Login MailPoet – Login users from newsletter Maintenance & Trust
Maintenance Signals
Community Trust
Simple JWT Login MailPoet – Login users from newsletter Alternatives
Simple JWT Login – Allows you to use JWT on REST endpoints.
simple-jwt-login
Enhance the WordPress REST API with JWT authentication for secure access by mobile apps, external sites, and third-party services.
JWT Authentication for WP REST API
jwt-authentication-for-wp-rest-api
Extends the WP REST API using JSON Web Tokens Authentication as an authentication method.
JWT Authentication for WP REST APIs
wp-rest-api-authentication
Secure and protect WordPress REST API from unauthorized access using JWT token, Basic Authentication, API Key, OAuth 2, or external token.
WPBruiser {no- Captcha anti-Spam}
goodbye-captcha
An extremely powerful antispam plugin that blocks spam-bots without annoying captcha images.
JWT Auth – WordPress JSON Web Token Authentication
jwt-auth
Create JSON Web Token Authentication in WordPress.
Simple JWT Login MailPoet – Login users from newsletter Developer Profile
2 plugins · 5K total installs
How We Detect Simple JWT Login MailPoet – Login users from newsletter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-jwt-login-mailpoet/assets/css/style.css/wp-content/plugins/simple-jwt-login-mailpoet/assets/js/scripts.js/wp-content/plugins/simple-jwt-login-mailpoet/assets/js/scripts.jssimple-jwt-login-mailpoet/assets/css/style.css?ver=simple-jwt-login-mailpoet/assets/js/scripts.js?ver=