emfluence Marketing Platform Security & Risk Analysis

wordpress.org/plugins/wp-emfluence

Easily add forms to your website for contacts to add or update their details in your emfluence Marketing Platform account.

20 active installs v2.13 PHP 5.6+ WP 4.0+ Updated Jun 13, 2022
apiemailemail-marketingemailmarketingemfluence
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is emfluence Marketing Platform Safe to Use in 2026?

Generally Safe

Score 85/100

emfluence Marketing Platform has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The wp-emfluence plugin version 2.13 presents a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has a high percentage of properly escaped output. It also avoids bundling external libraries, reducing the risk of carrying outdated and vulnerable code. Furthermore, there is no recorded history of known vulnerabilities (CVEs), which is a strong indicator of past security diligence.

However, significant concerns arise from the attack surface analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks. This creates a direct entry point for unauthenticated users to interact with potentially sensitive functionality, increasing the risk of exploitation. The absence of nonce checks on these AJAX handlers further exacerbates this risk, as it leaves the door open for Cross-Site Request Forgery (CSRF) attacks. While taint analysis shows no critical or high-severity flows, the lack of proper authorization on entry points is a fundamental security flaw that could be exploited if not properly mitigated within the AJAX handler code itself.

In conclusion, while the plugin has strong internal code hygiene concerning database interactions and output handling, the unprotected AJAX endpoints are a critical weakness. The lack of a vulnerability history is a positive sign, but it does not negate the immediate risks introduced by the exposed and unauthenticated entry points. Developers should prioritize implementing proper authentication and authorization checks for these AJAX handlers to secure the plugin.

Key Concerns

  • AJAX handlers without auth checks
  • Missing nonce checks on AJAX handlers
Vulnerabilities
None known

emfluence Marketing Platform Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

emfluence Marketing Platform Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

emfluence Marketing Platform Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
77 escaped
Nonce Checks
0
Capability Checks
1
File Operations
3
External Requests
1
Bundled Libraries
0

Output Escaping

91% escaped85 total outputs
Attack Surface
2 unprotected

emfluence Marketing Platform Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_emfl_form_store_searchinc\store_locator.php:36
noprivwp_ajax_emfl_form_store_searchinc\store_locator.php:37
WordPress Hooks 24
actionadmin_menuadmin.php:16
actionadmin_initadmin.php:42
actionadmin_enqueue_scriptsadmin.php:67
actionadmin_noticesadmin.php:157
actionwidgets_initemfluence.php:36
actionplugins_loadedemfluence.php:43
actionadmin_initinc\discount_code.php:14
filteremfl_widget_custom_field_typesinc\discount_code.php:15
filteremfl_widget_before_contact_saveinc\discount_code.php:16
actionemfl_widget_before_submitinc\recaptcha.php:9
filteremfl_widget_validateinc\recaptcha.php:10
actionadmin_initinc\recaptcha.php:11
actionemfl_plugin_settings_pageinc\recaptcha.php:12
actioninitinc\store_locator.php:25
filteremfl_widget_custom_field_typesinc\store_locator.php:30
filteremfl_widget_before_fieldinc\store_locator.php:31
actionemfl_widget_before_submitinc\store_locator.php:32
filteremfl_widget_before_contact_saveinc\store_locator.php:33
filteremfl_widget_validateinc\store_locator.php:34
filteremfl_widget_editor_after_sectionsinc\store_locator.php:35
actionadd_meta_boxesinc\woocommerce.php:15
actionsave_postinc\woocommerce.php:16
actionwoocommerce_checkout_order_processedinc\woocommerce.php:17
actionwoocommerce_order_refundedinc\woocommerce.php:18
Maintenance & Trust

emfluence Marketing Platform Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 13, 2022
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs20
Developer Profile

emfluence Marketing Platform Developer Profile

emfluence interactive marketing

3 plugins · 120 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect emfluence Marketing Platform

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-emfluence/css/widget-settings.css/wp-content/plugins/wp-emfluence/js/widget-settings.min.js
Version Parameters
wp-emfluence/css/widget-settings.css?ver=wp-emfluence/js/widget-settings.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
emfluenceemfl_widget
HTML Comments
<!-- emfluence Marketing Platform Global Settings --><!-- emfluence Settings --><!-- Welcome! Please enter your api credentials below to begin. Once authenticated, you can create as many widgets as you need. Settings are saved per widget. --><!-- Access token validated. -->
Data Attributes
name="emfluence_global[api_key]"name="emfluence_global[blacklist_domains]"id="api_key"id="blacklist_domains"
JS Globals
ajax_object
FAQ

Frequently Asked Questions about emfluence Marketing Platform