Simple JWT Login MailPoet – Login users from newsletter Security & Risk Analysis

wordpress.org/plugins/simple-jwt-login-mailpoet

The Simple JWT Login MailPoet plugin is an add-on for the Simple-Jwt-Login plugin.

0 active installs v1.0.3 PHP 5.5+ WP 4.4.0+ Updated Mar 18, 2026
auto-loginjwtmailpoetnewsletter-jwtnewsletter-login
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple JWT Login MailPoet – Login users from newsletter Safe to Use in 2026?

Generally Safe

Score 100/100

Simple JWT Login MailPoet – Login users from newsletter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "simple-jwt-login-mailpoet" v1.0.2 plugin presents a mixed security posture. On the positive side, the static analysis indicates a lack of identified attack surface points (AJAX, REST API, shortcodes, cron), no dangerous functions, and all SQL queries utilizing prepared statements. The vulnerability history is also clean, with no recorded CVEs, suggesting a stable and potentially well-maintained codebase in terms of known external threats. However, a significant concern arises from the output escaping. With 24 total outputs and 0% properly escaped, this opens the door to potential Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is not correctly sanitized before being displayed to users could be exploited by attackers. The absence of nonce checks and capability checks on entry points, although the entry points themselves are reported as zero, is a point of caution. If any new entry points were to be introduced or if the initial analysis missed something, this could lead to significant security risks. The lack of taint analysis results is also noteworthy; it's unclear if this is because no flows were analyzed or if no potentially malicious flows were detected. Overall, while the plugin shows good practices in terms of SQL and a clean vulnerability history, the critical lack of output escaping is a substantial weakness that requires immediate attention.

Key Concerns

  • 0% of outputs properly escaped
  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

Simple JWT Login MailPoet – Login users from newsletter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Simple JWT Login MailPoet – Login users from newsletter Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
v1.0.0
v0.1.1
v0.1.0
Code Analysis
Analyzed Mar 17, 2026

Simple JWT Login MailPoet – Login users from newsletter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped24 total outputs
Attack Surface

Simple JWT Login MailPoet – Login users from newsletter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filtermailpoet_newsletter_shortcodemailpoet.php:9
actionadmin_menusimple-jwt-login-mailpoet.php:13
actionadmin_noticessimple-jwt-login-mailpoet.php:15
actionplugins_loadedsimple-jwt-login-mailpoet.php:37
Maintenance & Trust

Simple JWT Login MailPoet – Login users from newsletter Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 18, 2026
PHP min version5.5
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Simple JWT Login MailPoet – Login users from newsletter Developer Profile

Nicu Micle

2 plugins · 5K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
612 days
View full developer profile
Detection Fingerprints

How We Detect Simple JWT Login MailPoet – Login users from newsletter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-jwt-login-mailpoet/assets/css/style.css/wp-content/plugins/simple-jwt-login-mailpoet/assets/js/scripts.js
Script Paths
/wp-content/plugins/simple-jwt-login-mailpoet/assets/js/scripts.js
Version Parameters
simple-jwt-login-mailpoet/assets/css/style.css?ver=simple-jwt-login-mailpoet/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Simple JWT Login MailPoet – Login users from newsletter