
WP Subscribe Security & Risk Analysis
wordpress.org/plugins/wp-subscribeWP Subscribe is a simple but powerful subscription plugin which supports MailChimp, Aweber and Feedburner.
Is WP Subscribe Safe to Use in 2026?
Use With Caution
Score 61/100WP Subscribe has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "wp-subscribe" plugin exhibits a mixed security posture. While it demonstrates good practices in areas like SQL query sanitization and output escaping, significant concerns arise from its attack surface and vulnerability history. The presence of four unprotected AJAX handlers represents a substantial risk, as these can be directly exploited by unauthenticated users to perform unintended actions. The single critical taint flow also highlights a potential for serious vulnerabilities, even if it's not directly tied to a specific CVE in the provided history.
The plugin's vulnerability history, with two known CVEs and one currently unpatched, points to a recurring pattern of security weaknesses. The common vulnerability types listed (Missing Authorization, Cross-site Scripting) align with the concerns identified in the static analysis. The fact that the last vulnerability was dated 2026-01-26 suggests a potential for ongoing or recently discovered issues, making the unpatched CVE particularly alarming. Overall, while strengths exist, the unpatched CVE and the large number of unprotected entry points necessitate immediate attention.
Key Concerns
- Unprotected AJAX handlers (4)
- Unpatched CVE (1)
- Critical severity taint flow (1)
- Missing capability checks on AJAX
- Low output escaping coverage (1%)
WP Subscribe Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Subscribe <= 1.2.16 - Missing Authorization
WP Subscribe <= 1.2.12 - Authenticated (Admin+) Stored Cross-Site Scripting
WP Subscribe Release Timeline
WP Subscribe Code Analysis
Output Escaping
Data Flow Analysis
WP Subscribe Attack Surface
AJAX Handlers 5
WordPress Hooks 6
Maintenance & Trust
WP Subscribe Maintenance & Trust
Maintenance Signals
Community Trust
WP Subscribe Alternatives
Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
email-subscribers
Add subscription forms on the website and send newsletters & automatically send post notification about new blog posts once it gets published.
Autoship Cloud for WooCommerce Subscription Products
autoship-cloud
Use one plugin to automate repeat orders, product subscriptions, and scheduled deliveries for your WooCommerce subscriptions products.
SendSquared – Email Marketing, Lead Generation, Popup & Post Emailer
adbase-ai-popup-growth
Enables you to install popups, email posts, install subscribe forms and lightweight analytics. The design and data focused email marketing platform.
Jamie’s WP Arrow Newsletter Subscriber
jamies-wp-arrow-newsletter-subscriber
A Widget to add an Arrow newsletter subscription form .
WP Simple Subscriber
wp-simple-subscriber
Allows you to collect subscribers via a simple form (in a shortcode) or your own custom form.
WP Subscribe Developer Profile
7 plugins · 38K total installs
How We Detect WP Subscribe
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-subscribe/css/wps-main.css/wp-content/plugins/wp-subscribe/css/wps-responsive.css/wp-content/plugins/wp-subscribe/js/wps-validate.js/wp-content/plugins/wp-subscribe/js/wps-connect.js/wp-content/plugins/wp-subscribe/js/wps-shortcode.js/wp-content/plugins/wp-subscribe/js/wps-admin.js/wp-content/plugins/wp-subscribe/js/wps-validate.js/wp-content/plugins/wp-subscribe/js/wps-connect.js/wp-content/plugins/wp-subscribe/js/wps-shortcode.js/wp-content/plugins/wp-subscribe/js/wps-admin.jswp-subscribe/css/wps-main.css?ver=wp-subscribe/css/wps-responsive.css?ver=wp-subscribe/js/wps-validate.js?ver=wp-subscribe/js/wps-connect.js?ver=wp-subscribe/js/wps-shortcode.js?ver=wp-subscribe/js/wps-admin.js?ver=HTML / DOM Fingerprints
wps-subscribe-formwps-subscribe-successwps-subscribe-errorwp-subscribe-noticewpsubscribe-dismiss-notice<!-- WP Subscribe Widget --><!-- WP Subscribe Form --><!-- Shortcode WP Subscribe --><!-- Shortcode WP Subscribe Pro -->data-wps-email-labeldata-wps-name-labeldata-wps-submit-textdata-wps-servicedata-wps-api-keydata-wps-list-id+1 morewps_ajax_objectwps_validation_messageswps_connect_object/wp-json/wp-subscribe/v1/subscribe/wp-json/wp-subscribe/v1/connect<form class="wps-subscribe-form" method="post"><div class="wps-subscribe-success"><div class="wps-subscribe-error">