
Subscribe to Unlock Lite – Opt In Content Locker Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/subscribe-to-unlock-liteLock your content using our Subscription Form and collect email address and grow your subscribers organically. 5 pre designed template, 2 lock modes, …
Is Subscribe to Unlock Lite – Opt In Content Locker Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 94/100Subscribe to Unlock Lite – Opt In Content Locker Plugin for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The 'subscribe-to-unlock-lite' v1.3.1 plugin exhibits a mixed security posture. While it shows some positive signs like a low number of file operations and no external HTTP requests, significant concerns exist regarding its attack surface and vulnerability history. A notable weakness is the presence of 8 unprotected AJAX handlers, representing a large entry point for potential attacks. The taint analysis also flagged a high severity flow with unsanitized paths, which is a critical concern, even if it's not currently a listed CVE. The plugin's history of 2 high severity vulnerabilities, specifically 'PHP Remote File Inclusion,' even though they are currently patched, suggests a recurring pattern of insecure coding practices that could resurface. The presence of unsanitized paths in the taint analysis, combined with the historical RFI vulnerabilities, points to a potential for attackers to manipulate file operations.
Despite the positive aspects like a good percentage of prepared SQL statements and proper output escaping, the unprotected AJAX handlers and the historical RFI vulnerabilities are significant risks. The untainted paths identified in the taint analysis, coupled with the history of RFI, strongly suggest a susceptibility to file inclusion vulnerabilities. Therefore, while not entirely lacking in good practices, the plugin carries a notable risk due to its exposed entry points and past security flaws.
Key Concerns
- Unprotected AJAX handlers
- Taint flow with unsanitized paths (high severity)
- History of High severity RFI vulnerabilities
- Large attack surface without auth checks
Subscribe to Unlock Lite – Opt In Content Locker Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Subscribe to Unlock Lite <= 1.3.0 - Authenticated (Subscriber+) Local File Inclusion
Subscribe to Unlock Lite <= 1.3.0 - Authenticated (Contributor+) Local File Inclusion
Subscribe to Unlock Lite – Opt In Content Locker Plugin for WordPress Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Subscribe to Unlock Lite – Opt In Content Locker Plugin for WordPress Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Subscribe to Unlock Lite – Opt In Content Locker Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Subscribe to Unlock Lite – Opt In Content Locker Plugin for WordPress Alternatives
Super Social Content Locker Lite
super-social-content-locker-lite
GROW YOUR SOCIAL MEDIA FOLLOWERS NOW WITH SUPER SOCIAL CONTENT LOCKER!
Unloct
unloct
Unloct is a microsubscription platform. Subscribers pay one monthly fee for unlimited access to an entire network of creators.
Newsletter – Send awesome emails from WordPress
newsletter
An email marketing tool for your blog: subscription forms to create your lists with unlimited subscribers and newsletters.
Hustle – Email Marketing, Lead Generation, Optins, Popups
wordpress-popup
Setup email optin forms, popups, newsletter forms & subscription forms to generate email leads with the best marketing popup builder
Advanced Excerpt
advanced-excerpt
Control the appearance of WordPress post excerpts
Subscribe to Unlock Lite – Opt In Content Locker Plugin for WordPress Developer Profile
8 plugins · 4K total installs
How We Detect Subscribe to Unlock Lite – Opt In Content Locker Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subscribe-to-unlock-lite/fontawesome/css/all.min.css/wp-content/plugins/subscribe-to-unlock-lite/css/stul-frontend.css/wp-content/plugins/subscribe-to-unlock-lite/css/stul-rtl.css/wp-content/plugins/subscribe-to-unlock-lite/css/stul-backend.css/wp-content/plugins/subscribe-to-unlock-lite/css/stul-tinymce.css/wp-content/plugins/subscribe-to-unlock-lite/css/stul-preview.css/wp-content/plugins/subscribe-to-unlock-lite/js/stul-frontend.js/wp-content/plugins/subscribe-to-unlock-lite/js/stul-backend.jssubscribe-to-unlock-lite/fontawesome/css/all.min.css?ver=subscribe-to-unlock-lite/css/stul-frontend.css?ver=subscribe-to-unlock-lite/css/stul-rtl.css?ver=subscribe-to-unlock-lite/css/stul-backend.css?ver=subscribe-to-unlock-lite/css/stul-tinymce.css?ver=subscribe-to-unlock-lite/js/stul-frontend.js?ver=subscribe-to-unlock-lite/js/stul-backend.js?ver=subscribe-to-unlock-lite/css/stul-preview.css?ver=HTML / DOM Fingerprints
stul-content-lockstul-form-wrap<!-- STUL Content Lock Start --><!-- STUL Content Lock End --><!-- STUL FORM PREVIEW --><!-- STUL FORM PREVIEW END -->data-stul-content-iddata-stul-form-iddata-stul-form-typedata-stul-form-titlestul_frontend_objstul_backend_obj[stul_unlock_form[stul_unlock_content