
WP SendFox Security & Risk Analysis
wordpress.org/plugins/wp-sendfoxCapture emails and add them to your SendFox list via comments, registration, WooCommerce checkout, Gutenberg page or Divi Builder page.
Is WP SendFox Safe to Use in 2026?
Use With Caution
Score 63/100WP SendFox has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The wp-sendfox plugin exhibits a mixed security posture. While it avoids using dangerous functions and has some rudimentary checks in place like nonce and capability checks, significant concerns arise from its attack surface and data handling practices. The presence of multiple AJAX handlers without authentication is a major vulnerability, potentially allowing unauthorized users to interact with sensitive plugin functionalities. Furthermore, the lack of prepared statements for SQL queries and the low percentage of properly escaped output suggest a high risk of SQL injection and cross-site scripting (XSS) vulnerabilities, respectively. The vulnerability history, with two medium-severity CVEs including an unpatched one, reinforces these concerns. The repeated exposure of sensitive information and missing authorization vulnerabilities in its past indicate a recurring pattern of security weaknesses in how the plugin handles user access and data. Despite a relatively small attack surface in terms of entry points, the lack of robust security measures on those entry points, coupled with historical issues, elevates the overall risk of this plugin.
Key Concerns
- Unpatched CVE
- Multiple AJAX handlers without auth checks
- Raw SQL queries without prepared statements
- Low percentage of properly escaped output
- One unsanitized taint flow
- Missing authorization vulnerabilities in history
- Exposure of sensitive information vulnerabilities in history
WP SendFox Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP SendFox <= 1.3.1 - Unauthenticated Information Disclosure
WP SendFox <= 1.3.0 - Missing Authorization
WP SendFox Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP SendFox Attack Surface
AJAX Handlers 5
WordPress Hooks 24
Maintenance & Trust
WP SendFox Maintenance & Trust
Maintenance Signals
Community Trust
WP SendFox Alternatives
W2P: Pipedrive CRM Integration for WooCommerce
w2p-pipedrive-crm-integration-for-woocommerce
Sync your WooCommerce store with Pipedrive to effortlessly manage customer activity and orders in one place.
SA Integrations For Google Sheets
sa-integrations-for-google-sheets
This plugin connects your WordPress website with Google Sheets, enabling automatic synchronization of form submissions and WooCommerce order data.
WP Crontrol
wp-crontrol
WP Crontrol enables you to take control of the cron events on your WordPress website.
Advanced Order Export For WooCommerce
woo-order-export-lite
Export WooCommerce orders to Excel, CSV, XML, JSON, PDF and HTML. Best free order export plugin for WooCommerce.
WPC Smart Quick View for WooCommerce
woo-smart-quick-view
WPC Smart Quick View allows users to get a quick look at products without opening the product page.
WP SendFox Developer Profile
2 plugins · 1K total installs
How We Detect WP SendFox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-sendfox/assets/css/sf-frontend.css/wp-content/plugins/wp-sendfox/assets/js/sf-frontend.js/wp-content/plugins/wp-sendfox/assets/js/gb-sf4wp.js/wp-content/plugins/wp-sendfox/assets/js/sf-frontend.js/wp-content/plugins/wp-sendfox/assets/js/gb-sf4wp.jswp-sendfox/assets/css/sf-frontend.css?ver=wp-sendfox/assets/js/sf-frontend.js?ver=wp-sendfox/assets/js/gb-sf4wp.js?ver=HTML / DOM Fingerprints
sf-inputsf-labelsf-submitgb_sf4wp_formdata-sf4wp-idgb_sf4wp_vars