
WP Funnel Manager Security & Risk Analysis
wordpress.org/plugins/wp-funnel-managerOrganises content into multi-step funnels.
Is WP Funnel Manager Safe to Use in 2026?
Mostly Safe
Score 76/100WP Funnel Manager is generally safe to use. 1 past CVE were resolved. Keep it updated.
The static analysis of wp-funnel-manager v1.4.0 indicates a generally strong security posture. The plugin demonstrates good security practices by not exposing any direct entry points through AJAX, REST API, shortcodes, or cron events without proper authentication or permission checks. The code further reinforces this by consistently using prepared statements for SQL queries, properly escaping all output, and implementing nonce and capability checks for its defined functions. The absence of dangerous functions, file operations, and external HTTP requests also contributes positively to its security profile.
However, a significant concern arises from the vulnerability history. The plugin has a known unpatched high-severity vulnerability related to deserialization of untrusted data, which was last reported in 2025. This single, severe historical issue overshadows the otherwise clean static analysis. While the current code might not exhibit immediate exploitable flaws in the analyzed static code, the historical vulnerability indicates a potential for latent weaknesses or a past failure in sanitizing user-supplied data in specific contexts, particularly concerning deserialization, which can lead to remote code execution if exploited. The presence of a high-severity, unpatched CVE is a critical risk that needs immediate attention.
In conclusion, while wp-funnel-manager v1.4.0 exhibits good coding practices in static analysis, the presence of an unpatched high-severity vulnerability significantly elevates the risk. Users should be strongly advised to avoid this version until the known deserialization vulnerability is patched and verified. The plugin has a strength in its well-defined and protected attack surface, but its primary weakness lies in its vulnerability history, which points to a critical risk that has not been addressed.
Key Concerns
- Unpatched high severity CVE (Deserialization)
WP Funnel Manager Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Funnel Manager <= 1.4.0 - Unauthenticated PHP Object Injection
WP Funnel Manager Code Analysis
Output Escaping
WP Funnel Manager Attack Surface
WordPress Hooks 37
Maintenance & Trust
WP Funnel Manager Maintenance & Trust
Maintenance Signals
Community Trust
WP Funnel Manager Alternatives
WPMktgEngine
wpmktgengine
WPMktgEngine turns your WordPress site into a marketing engine for your business. A comprehensive online marketing platform.
LandingRabbit
landingrabbit
Bring your LandingRabbit pages into WordPress and publish them with Elementor and Gutenberg.
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode
coming-soon
Easy Drag & Drop Page Builder. A complete solution to create a WordPress Website, Custom Themes, Landing Pages, Coming Soon & Maintenance Mode Pages.
Page Builder: Pagelayer – Drag and Drop website builder
pagelayer
The most advanced frontend drag & drop page builder. Pagelayer is a light weight but extremely powerful Website Builder.
WP Funnel Manager Developer Profile
2 plugins · 10 total installs
How We Detect WP Funnel Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-funnel-manager/css/style.css/wp-content/plugins/wp-funnel-manager/js/main.js/wp-content/plugins/wp-funnel-manager/js/main.jswp-funnel-manager/css/style.css?ver=wp-funnel-manager/js/main.js?ver=HTML / DOM Fingerprints
wpfunnel-admin-notice<!-- If this file is called directly, abort. --><!-- WPCS: input var okay, CSRF okay. --><!-- WPCS: input var okay. --><!-- Plugin Name: WP Funnel Manager -->+20 moredata-wpfunnel-iddata-wpfunnel-typewpfunnelWP_Funnel_Manager