
Wp Subcribe Author Security & Risk Analysis
wordpress.org/plugins/wp-subscribe-authorWp Subscribe Author plugin is help subscriber to follow his/her favorite author.
Is Wp Subcribe Author Safe to Use in 2026?
Generally Safe
Score 85/100Wp Subcribe Author has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-subscribe-author plugin v1.8 presents a concerning security posture primarily due to its lack of robust input validation and authentication checks. While the plugin demonstrates good practices by largely utilizing prepared statements for its SQL queries and avoiding external HTTP requests and file operations, the static analysis reveals significant weaknesses. The presence of four unprotected AJAX handlers constitutes a substantial attack surface, making the plugin vulnerable to unauthorized actions if these handlers are exploitable. Furthermore, the taint analysis indicates seven critical flows with unsanitized paths, suggesting a high likelihood of injection vulnerabilities, particularly given the absence of any nonce or capability checks. The plugin's vulnerability history of zero known CVEs is a positive sign, but it does not negate the immediate risks identified in the code analysis. The lack of any recorded past vulnerabilities could imply either a history of strong security or simply a lack of discovery, which is a risky assumption when combined with the current code quality.
Key Concerns
- 4 unprotected AJAX handlers
- 7 critical taint flows with unsanitized paths
- 0 Nonce checks
- 0 Capability checks
- 4% properly escaped output
- 1 Dangerous function (create_function)
Wp Subcribe Author Security Vulnerabilities
Wp Subcribe Author Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Wp Subcribe Author Attack Surface
AJAX Handlers 4
Shortcodes 2
WordPress Hooks 16
Maintenance & Trust
Wp Subcribe Author Maintenance & Trust
Maintenance Signals
Community Trust
Wp Subcribe Author Alternatives
KolorWeb Access Admin Notification: extreme rescue for unauthorized admin logins
kolorweb-access-admin-notification
Extreme rescue for unauthorized admin logins.
Mail to Users
mail2users
Email to users about new posts and pages. Send custom emails. Email to users about latest woocommerce products. Emails privacy.
Manage Notification E-mails
manage-notification-emails
Enable and disable email notifications that WordPress sends to the admin and user. Works perfectly with many other plugins!
Customize WordPress Emails and Alerts – Better Notifications for WP
bnfw
Supercharge your WordPress email notifications using a WYSIWYG editor and shortcodes. Default and new notifications available. Add-ons available.
Notification – Custom Notifications and Alerts for WordPress
notification
Take full control of WordPress emails and notifications. Replace default messages, add custom triggers, and send alerts via email, webhook, Slack, and …
Wp Subcribe Author Developer Profile
2 plugins · 30 total installs
How We Detect Wp Subcribe Author
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-subscribe-author/js/jquery.hovercard.min.js/wp-content/plugins/wp-subscribe-author/js/wpsa-subscribe-author.js/wp-content/plugins/wp-subscribe-author/js/jquery.hovercard.min.js/wp-content/plugins/wp-subscribe-author/js/wpsa-subscribe-author.jsHTML / DOM Fingerprints
data-wpsa-ajax-suportwpsa_ajax_suport[favourite-author]