Teletter Telegram Newsletter Security & Risk Analysis

wordpress.org/plugins/teletter-telegram-newsletter

Send Newsletter from Telegram Bot, user can subscribe to your site from Telegram Bot.

10 active installs v1.3 PHP + WP 3.0.1+ Updated Dec 30, 2015
newslettertelegramtelegram-bottelegram-newslettertranslate-ready
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Teletter Telegram Newsletter Safe to Use in 2026?

Generally Safe

Score 85/100

Teletter Telegram Newsletter has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The 'teletter-telegram-newsletter' plugin v1.3 demonstrates several positive security practices, including the absence of known vulnerabilities (CVEs) and a clean taint analysis report, indicating no critical or high severity flows were detected. Furthermore, all detected SQL queries utilize prepared statements, which is a strong defense against SQL injection. The plugin also implements some nonce and capability checks, along with proper handling of external HTTP requests.

However, there are notable areas for concern. The most significant is the low rate of proper output escaping, with only 44% of outputs being escaped. This leaves a substantial portion of data potentially vulnerable to cross-site scripting (XSS) attacks, especially as the plugin interacts with users or displays external data. While the static analysis reported no direct XSS findings, the lack of consistent escaping significantly increases the risk. The presence of file operations and cron events, while not inherently insecure, do represent potential attack vectors if not handled with extreme care, especially in conjunction with insufficient output sanitization.

Overall, the plugin has a decent foundation with its secure handling of database queries and lack of historical vulnerabilities. However, the widespread lack of output escaping is a serious weakness that significantly elevates the risk profile. Addressing the output escaping issue should be the highest priority to improve the plugin's security posture. The absence of direct security issues in static and taint analysis is encouraging, but the low escape rate mitigates this positive finding.

Key Concerns

  • Low output escaping rate (44%)
  • File operations present (4)
  • Cron events present (3)
Vulnerabilities
None known

Teletter Telegram Newsletter Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Teletter Telegram Newsletter Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
19 escaped
Nonce Checks
2
Capability Checks
2
File Operations
4
External Requests
1
Bundled Libraries
0

Output Escaping

44% escaped43 total outputs
Attack Surface

Teletter Telegram Newsletter Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_initincludes\api-settings.php:2
actionadd_meta_boxesincludes\notification-metabox.php:2
actionsave_postincludes\notification-metabox.php:57
filterpage_attributes_dropdown_pages_argsincludes\pagetemplate.php:43
filterwp_insert_post_dataincludes\pagetemplate.php:50
filtertemplate_includeincludes\pagetemplate.php:58
actionplugins_loadedincludes\pagetemplate.php:137
actioninitincludes\users-save.php:42
filtermanage_edit-subscriber_columnsincludes\users-save.php:44
actionmanage_subscriber_posts_custom_columnincludes\users-save.php:62
actionadd_meta_boxesincludes\users-save.php:164
actionsave_postincludes\users-save.php:218
actionplugins_loadedtelegram.php:14
actionadmin_menutelegram.php:18
actioninittelegram.php:77
actioninittelegram.php:104

Scheduled Events 3

getupdates
getupdates
getupdates
Maintenance & Trust

Teletter Telegram Newsletter Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedDec 30, 2015
PHP min version
Downloads10K

Community Trust

Rating88/100
Number of ratings9
Active installs10
Developer Profile

Teletter Telegram Newsletter Developer Profile

Websima

2 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Teletter Telegram Newsletter

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/teletter-telegram-newsletter/includes/dashicon.png
Version Parameters
teletter-telegram-newsletter/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wrap
FAQ

Frequently Asked Questions about Teletter Telegram Newsletter