
WP Centrico Security & Risk Analysis
wordpress.org/plugins/wp-centricoThis plugin allows you to manage the subscription to centrico, your users will be registered in centrico and will receive your newsletter.
Is WP Centrico Safe to Use in 2026?
Generally Safe
Score 85/100WP Centrico has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-centrico plugin v1.1.6 exhibits a mixed security posture, with some positive indicators but significant areas of concern. While the plugin has a small attack surface and no known CVEs, the static analysis reveals several weaknesses. The most concerning is the taint analysis, which identified 2 high-severity flows with unsanitized paths, indicating a potential for vulnerabilities if these flows are exploitable. Furthermore, a low percentage of output is properly escaped (29%), suggesting a risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce and capability checks on all entry points is a critical oversight, especially given the potential for malicious input via the identified taint flows.
The lack of vulnerability history is a positive sign, suggesting that the plugin has not been a frequent target or source of security issues. However, this should not overshadow the risks identified in the code analysis. The plugin has strengths in its limited attack surface and the use of prepared statements for a majority of its SQL queries. Nevertheless, the identified taint flows and inadequate output escaping present tangible security risks that need to be addressed. A balance of strengths and weaknesses means the plugin is not inherently insecure but requires immediate attention to its identified vulnerabilities to improve its overall security.
Key Concerns
- High severity taint flows with unsanitized paths
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
WP Centrico Security Vulnerabilities
WP Centrico Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Centrico Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
WP Centrico Maintenance & Trust
Maintenance Signals
Community Trust
WP Centrico Alternatives
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
fluent-crm
The easiest and fastest Email Marketing, Newsletter, Marketing Automation Plugin & CRM Solution for WordPress
Groundhogg — CRM, Newsletters, and Marketing Automation
groundhogg
Groundhogg is the best WordPress CRM & Marketing Automation plugin. Create flows, email campaigns, and have a CRM all within your WordPress site.
Gravity Forms Klaviyo Add-On
gf-klaviyo-add-on
Gravity Forms Klaviyo Add-On seamlessly integrates Gravity Forms with Klaviyo, enabling powerful email marketing automation.
SALESmanago & Leadoo
salesmanago
AI-powered Customer Engagement Platform for impact-hungry eCommerce marketing teams
Smart Marketing SMS and Newsletters Forms
smart-marketing-for-wp
E-commerce Automation Engine: Product sync, Track & Engage, and abandoned cart recovery via Email and SMS for WooCommerce stores.
WP Centrico Developer Profile
1 plugin · 10 total installs
How We Detect WP Centrico
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-centrico/js/script.jsHTML / DOM Fingerprints
Centrico_widgetdisabledInputCentrico_Widget[centrico]