Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress
by Icegram · Email & Marketing
Also makes 7 other plugins · 64.3K+ installs across the portfolio →
Add subscription forms on the website and send newsletters & automatically send post notification about new blog posts once it gets published.
97 health vs 63 average across 1,298 Email & Marketing plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
57.2K
now · peak 183.2K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
31
releases in the last 12 months
1mo ago
latest release · v5.9.30
374
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 54% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “50K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-03-10 · 1,481 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A declining trend compresses what a buyer would pay.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ sylvakleemann2mo ago
Easy to use, works reliably, really great support!
Read on wp.org ↗ - ★★★★★ shikhargoel19903mo ago
I’ve been using Icegram Express for a long time and it has made email marketing inside WordPress really simple. Creating subscriber lists, sending newsletters, and setting up post notification emails is easy and beginner-friendly. The interface is clean, easy to use, and saves a lot of time. What I like most is the email deliverability. Emails are sent reliably and everything works smoothly inside WordPress without needing extra tools.The support team is also responsive and helpful whenever assistance is needed. Overall, it’s a solid plugin that simply gets the job done without making things complicated.
Read on wp.org ↗ - ★★★★★ cabbagetree5mo ago
easy to use and follow… can be used for sending newsletters easily …
Read on wp.org ↗ - ★★★★★ jgfishman6mo ago
I am very happy with Icegram Express. It is easy to add and customize for a variety of email campaigns. The customer service is also prompt and responsive. Overall, a great plugin!
Read on wp.org ↗ - ★★★★★ rdobrusin7mo ago
Excellent help in troubleshooting an issue I had encountered.
Read on wp.org ↗ - ★★★★★ wartin7mo ago
Works perfect. And if anything is not clear, the support is accurate and helpful!
Read on wp.org ↗ - ★★★★★ sayhi2lonnie7mo ago
I’ve been using this plug-in for a few years now, and it works flawlessly. Does exactly what it’s supposed to do, exactly what I need to do. I use it to send out email notifications for every new post I make. It staggers the sending of the messages, so they don’t get labeled as spam and blocked. I know there’s even more functionality that I haven’t used. So, this is a great plug-in. Don’t even hesitate to try it out. I encountered a small hiccup recently and the support team couldn’t have been more helpful. They dug up their sleeves and worked tirelessly to determine the root cause of the error (which wasn’t even the plug-ins fault), and identified the issue and provided the resolution. As soon as I implemented their fix, the emails immediately started sending again. Their communication was top notch and very easy to understand. I truly appreciate customer service that goes above and beyond expectations. Thank you again!
Read on wp.org ↗ - ★★★★★ druske9mo ago
Top Service and very friendly
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- — Version 5.9.30 Improvement: Added an option to “Resend” failed campaigns Fix: Resolved page caching compatibility issue [PRO] Fix: Form editor now shows updated list names after renaming 5.9.30
- — Version 5.9.29 New: Send emails using “Microsoft Outlook” API [MAX] Improvement: Contacts can now be sorted using “Last Opened” column in the Audience page Fix: Fixed report deletion issue on sites using RTL language 5.9.29
- — Version 5.9.28 New: Show unsubscribe stats in the audience dashboard New: Option to set title for “Popup form” Fix: Broadcast campaigns were showing the incorrect sent date in report 5.9.28
- — Version 5.9.27 Improvement: The audience edit modal can now be resized. Fix: Resolved the campaign preview issue in the Classic Editor. Fix: Sequence emails were getting triggered even when the status was set as “Draft” in some cases 5.9.27
- — Version 5.9.26 Improvement: Added the “Resend Failed Campaign” button to the Reports section. 5.9.26
- — Version 5.9.25 Improvement: Added bulk export option for campaign reports [MAX] Update: Tested up to WordPress 7.0 Fix: GDPR consent field now saves correctly when it contains a link Fix: Post Digest campaign sending notifications for 5.9.25
Known vulnerabilities
via Wordfence Intelligence43 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-03-03 CVE-2026-1651 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.9.16 Patched in 5.9.17
- 2025-12-11 CVE-2025-12348 Missing Authentication for Critical Function Affects <= 5.9.10 Patched in 5.9.11
- Medium · 5.3 Email Subscribers & Newsletters <= 5.9.10 - Missing Authentication to Unauthenticated Mailing Queue Trigger ↗2025-11-18 CVE-2025-12349 Missing Authentication for Critical Function Affects <= 5.9.10 Patched in 5.9.11
- Medium · 4.4 Email Subscribers & Newsletters <= 5.7.49 - Authenticated (Administrator+) Stored Cross-Site Scripting ↗2025-04-03 CVE-2025-0671 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.7.49 Patched in 5.7.50
- Medium · 4.4 Email Subscribers & Newsletters <= 5.7.51 - Authenticated (Administrator+) Stored Cross-Site Scripting ↗2025-03-27 CVE-2024-11924 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.7.51 Patched in 5.7.52
- 2024-12-23 CVE-2024-12567 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.7.44 Patched in 5.7.45
- 2024-12-23 CVE-2024-12568 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.7.44 Patched in 5.7.45
- 2024-12-23 CVE-2024-12566 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.7.44 Patched in 5.7.45
- 2024-12-23 CVE-2024-11636 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.7.44 Patched in 5.7.45
- 2024-12-16 CVE-2024-12311 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.7.43 Patched in 5.7.44
- 2024-10-01 CVE-2024-8254 Improper Control of Generation of Code ('Code Injection') Affects <= 5.7.34 Patched in 5.7.35
- 2024-07-01 CVE-2024-6172 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.7.25 Patched in 5.7.26
- Critical · 9.8 Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.23 - Unauthenticated SQL Injection via optin ↗2024-06-20 CVE-2024-5756 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.7.23 Patched in 5.7.24
- 2024-06-11 CVE-2024-4845 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.7.22 Patched in 5.7.23
- Critical · 9.8 Email Subscribers by Icegram Express <= 5.7.20 - Unauthenticated SQL Injection via hash ↗2024-06-04 CVE-2024-4295 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.7.20 Patched in 5.7.21
- Critical · 9.8 Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin <= 5.7.14 - Unauthenticated SQL Injection ↗2024-04-15 CVE-2024-2876 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.7.14 Patched in 5.7.15
- Medium · 4.4 Icegram Express <= 5.7.14 - Authenticated (Administrator+) Cross-Site Scripting via CSV import ↗2024-04-05 CVE-2024-2656 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.7.15 Patched in 5.7.16
- Medium · 6.1 Email Subscribers & Newsletters <= 5.7.11 - Reflected Cross-Site Scripting via campaign_id ↗2024-03-26 CVE-2024-22300 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 5.7.11 Patched in 5.7.12
- Critical · 9.1 Icegram Express <= 5.6.23 - Authenticated (Administrator+) Directory Traversal to Arbitrary File Read ↗2023-10-11 CVE-2023-5414 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 5.6.23 Patched in 5.6.24
- 2023-02-06 CVE-2022-45810 Improper Neutralization of Formula Elements in a CSV File Affects <= 5.5.2 Patched in 5.5.3
- 2022-11-21 CVE-2022-3981 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 5.4.19 Patched in 5.5.0
- 2022-02-11 CVE-2022-0439 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 5.3.2 Patched in 5.3.2
- 2020-07-16 CVE-2020-5768 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 4.5.1 Patched in 4.5.1
- 2019-11-13 CVE-2019-20361 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.3.0 Patched in 4.3.1
- 2019-11-13 CVE-2019-19980 Authentication Bypass by Primary Weakness Affects <= 4.2.2 Patched in 4.2.3
- Critical · 9.8 Email Subscribers & Newsletters <= 4.1.7 - SQL Injection ↗2019-07-22 CVE-2019-13569 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 4.1.7 Patched in 4.1.8
- 2019-07-12 CVE-2019-14364 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 4.1.6 Patched in 4.1.7
- 2018-05-28 CVE-2018-0602 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.4.12 Patched in 3.5.0
- 2018-01-24 CVE-2018-6015 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.4.7 Patched in 3.4.8
- 2015-08-10 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.9.1 Patched in 2.9.1
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 33 languages, 0 at 90% or more
Plus 9 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-07-23 60K+ → 50K+ down after 216 days in tier
- 2025-12-19 70K+ → 60K+ down after 225 days in tier
- 2025-05-08 80K+ → 70K+ down after 244 days in tier
- 2024-09-06 90K+ → 80K+ down after 202 days in tier
- 2024-02-17 100K+ → 90K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Hostinger Reach – AI-Powered Email Marketing for WordPress 1M+ installs · 4.3★ · 2 shared tags A
-
MailPoet – Newsletters, Email Marketing, and Automation 500K+ installs · 4.4★ · 2 shared tags A -
FireBox – WooCommerce Popup Builder, Exit Intent Popup, Email Optin & Cart Abandonment 7K+ installs · 4.8★ · 2 shared tags A -
Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails 5K+ installs · 4.7★ · 2 shared tags A -
MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails 1K+ installs · 4.5★ · 2 shared tags A
-
Gutena Newsletter – Subscriber Block & Connect Mailchimp 1K+ installs · 3.8★ · 2 shared tags B
Embed this report card
Drop a live Pulse card for Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/email-subscribers" width="480" height="300" style="border:0" loading="lazy" title="Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress — Plugin Pulse"></iframe> Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress: 50K+ active installs, 4.6★ (1,168 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/email-subscribers