Add-on Contact Form 7 – MailPoet 3 Security & Risk Analysis

wordpress.org/plugins/add-on-contact-form-7-mailpoet

Add a MailPoet 3 signup field to your Contact Form 7 forms.

4K active installs v1.3.22 PHP 7.2+ WP 5.3+ Updated Jan 30, 2025
cf7contact-form-7formformsmailpoet
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Add-on Contact Form 7 – MailPoet 3 Safe to Use in 2026?

Generally Safe

Score 92/100

Add-on Contact Form 7 – MailPoet 3 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of 'add-on-contact-form-7-mailpoet' v1.3.22 reveals a generally strong security posture, with no identified dangerous functions, SQL queries performed using prepared statements, no file operations, and no external HTTP requests. The absence of any known CVEs or historical vulnerabilities further strengthens this impression, suggesting a development team that is either very diligent or the plugin has not yet been a target for significant exploits. However, a critical concern arises from the complete lack of output escaping. With 51 outputs identified and none properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed back to users without proper sanitization could be exploited to inject malicious scripts, leading to session hijacking, defacement, or other harmful actions. Furthermore, the absence of nonce checks and capability checks, while not necessarily indicating a vulnerability in itself due to the zero attack surface, points to a potential gap in security best practices that could become a problem if new entry points are introduced in future versions. This lack of comprehensive security hardening, especially concerning output sanitization, significantly diminishes the plugin's otherwise positive security profile.

Key Concerns

  • Unescaped output
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Add-on Contact Form 7 – MailPoet 3 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Add-on Contact Form 7 – MailPoet 3 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
51
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped51 total outputs
Attack Surface

Add-on Contact Form 7 – MailPoet 3 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionplugins_loadedadd-on-contact-form-7-mailpoet.php:51
actionadmin_noticesadd-on-contact-form-7-mailpoet.php:74
actionadmin_noticesadd-on-contact-form-7-mailpoet.php:88
actionadmin_noticesadd-on-contact-form-7-mailpoet.php:119
actionwpcf7_initincludes\class-mailpoet-cf7-consent.php:12
actionadmin_initincludes\class-mailpoet-cf7-consent.php:15
actionadmin_initincludes\class-mailpoet-cf7-custom-field.php:17
actionwp_enqueue_scriptsincludes\class-mailpoet-cf7-integration.php:20
actionwp_footerincludes\class-mailpoet-cf7-integration.php:27
actionwpcf7_initincludes\class-mailpoet-cf7-integration.php:72
actionadmin_initincludes\class-mailpoet-cf7-integration.php:75
filterwpcf7_validate_mailpoetsignupincludes\class-mailpoet-cf7-integration.php:78
filterwpcf7_validate_mailpoetsignup*includes\class-mailpoet-cf7-integration.php:79
filterwpcf7_messagesincludes\class-mailpoet-cf7-integration.php:82
actionwpcf7_before_send_mailincludes\class-mailpoet-cf7-submit-form.php:42
actionwpcf7_initincludes\class-mailpoet-cf7-unsubscribe.php:13
actionadmin_initincludes\class-mailpoet-cf7-unsubscribe.php:16
Maintenance & Trust

Add-on Contact Form 7 – MailPoet 3 Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJan 30, 2025
PHP min version7.2
Downloads91K

Community Trust

Rating78/100
Number of ratings16
Active installs4K
Developer Profile

Add-on Contact Form 7 – MailPoet 3 Developer Profile

Tikweb Management

4 plugins · 7K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add-on Contact Form 7 – MailPoet 3

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-on-contact-form-7-mailpoet/assets/css/style.css/wp-content/plugins/add-on-contact-form-7-mailpoet/assets/js/scripts.js
Script Paths
/wp-content/plugins/add-on-contact-form-7-mailpoet/assets/js/scripts.js
Version Parameters
add-on-contact-form-7-mailpoet/assets/css/style.css?ver=add-on-contact-form-7-mailpoet/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
mailpoet-cf7-signup-fieldlistCheckboxwpcf7-mailpoetsignupmailpoet-cf7-consent-fieldmailpoet-cf7-unsubscribe-field
Data Attributes
data-key
JS Globals
mailpoet_cf7_segments_dataMailPoet_CF7_Integration
Shortcode Output
<label>Sign up for the newsletter</label><input type="checkbox" name="mailpoetsignup[]" value="id="mailpoetsignup"name="mailpoetsignup"
FAQ

Frequently Asked Questions about Add-on Contact Form 7 – MailPoet 3