
SubToMe Security & Risk Analysis
wordpress.org/plugins/subtomeThis widget adds a SubToMe button to your blog and allows people to subscribe to your content in one click.
Is SubToMe Safe to Use in 2026?
Generally Safe
Score 92/100SubToMe has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The subtome v1.5.6 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean taint analysis indicate a lack of critical vulnerabilities. The plugin also demonstrates good practices by exclusively using prepared statements for SQL queries and having no file operations or external HTTP requests. However, there are significant areas of concern, particularly regarding output escaping and the complete lack of nonce and capability checks. With 25% of outputs being improperly escaped, there's a notable risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is outputted without proper sanitization. Furthermore, the absence of nonce and capability checks on its single shortcode entry point makes it susceptible to Cross-Site Request Forgery (CSRF) and unauthorized actions if the shortcode performs any sensitive operations. While the attack surface is small, the lack of protective measures on the existing entry point is a weakness.
Key Concerns
- Low output escaping rate (25%)
- No nonce checks on entry points
- No capability checks on entry points
SubToMe Security Vulnerabilities
SubToMe Code Analysis
Output Escaping
SubToMe Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
SubToMe Maintenance & Trust
Maintenance Signals
Community Trust
SubToMe Alternatives
Subscribe Button by AddToAny
add-to-any-subscribe
Help visitors subscribe to your blog using email or any feed reader, such as Feedly, The Old Reader, Yahoo!, AOL, and many more feed services.
Simple Statistics for Feeds
simple-feed-stats
Tracks your feeds and displays your feed count via shortcode.
Subscribe Here Widget
subscribe-here-widget
Subscribe Here displays a visible plugin widget in the sidebar with Subscribe by Rss & Subscribe by Email(through Feedburner) options.
Cartograf Featured-image in Feed
cartograf-featured-image-in-feed
Includes the featured image of a post at the beginning of the item's content in the WordPress generated feeds. With this plugin, you no longer ne …
Follow WordPress Category Feeds
follow-category-feeds
This plugin adds link for the category feeds after post content.
SubToMe Developer Profile
3 plugins · 100 total installs
How We Detect SubToMe
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subtome/img/subtome-button.svgHTML / DOM Fingerprints
subtome-descriptionwidget_subtomedata-captiondata-descriptionsubtome_button_script<p class="subtome"><span class="subtome-description"><img src="" onclick="