
Active Campaign & WPForms Security & Risk Analysis
wordpress.org/plugins/active-campaign-wpformsThis plugin is a easy to use addon for WPform which helps to send form data to ActiveCampaign lists with very less configuration and easy to use inter …
Is Active Campaign & WPForms Safe to Use in 2026?
Generally Safe
Score 92/100Active Campaign & WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "active-campaign-wpforms" v1.1.1 exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential attack surface. Furthermore, the code signals indicate a lack of dangerous functions, all SQL queries utilize prepared statements, and there are no identified taint flows with unsanitized paths. The absence of known CVEs and a clean vulnerability history further reinforces this positive assessment. The plugin also avoids bundling external libraries, which can often introduce vulnerabilities if not kept up-to-date.
However, there are areas for improvement. The low percentage of properly escaped output (11%) is a significant concern. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate sanitization. The plugin also performs external HTTP requests, which, while not inherently a vulnerability, could be a vector for attacks if not handled securely or if the target endpoint is compromised. The lack of nonce checks and capability checks, while currently mitigated by the absence of unprotected entry points, would become a critical issue if any new entry points are introduced in the future without proper authorization controls. Overall, the plugin is secure in its current state due to a minimal attack surface and good data handling for SQL and taint, but the output escaping and lack of robust authorization checks on potential future entry points warrant attention.
Key Concerns
- Low output escaping percentage
- External HTTP requests without detail
- No nonce checks
- No capability checks
Active Campaign & WPForms Security Vulnerabilities
Active Campaign & WPForms Code Analysis
Output Escaping
Active Campaign & WPForms Attack Surface
WordPress Hooks 9
Maintenance & Trust
Active Campaign & WPForms Maintenance & Trust
Maintenance Signals
Community Trust
Active Campaign & WPForms Alternatives
Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-active-campaign
Send Contact Form 7, WPForms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to ActiveCampaign.
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR)
contact-form-7-image-captcha
Adds an Image CAPTCHA to Contact Form 7 and WPForms, GDPR ready, perfect WPForms or Contact Form 7 Spam Protection Image CAPTCHA, adds a honeypot
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
ActiveCampaign – The autonomous marketing platform
activecampaign-subscription-forms
Add ActiveCampaign contact forms and live chat to any post, page, or sidebar. Also enable ActiveCampaign site tracking for your WordPress blog.
Utimate Kit ( Styler ) for WPForms
styler-for-wpforms
Ultimate Kit for WPForms makes the task of designing WPForms an easy one.
Active Campaign & WPForms Developer Profile
9 plugins · 17K total installs
How We Detect Active Campaign & WPForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/active-campaign-wpforms/assets/admin.cssHTML / DOM Fingerprints
wpforms-panel-content-section-ac-integrationwpforms-panel-content-section-titlewpforms-builder-settings-block-contentfield-descwpforms-panel-field-ac-integration-list_ids-wrapwpforms-panel-field-email-recipientdata-parent="settings"data-class="email-recipient"