
Add-on Contact Form 7 – MailPoet 3 Security & Risk Analysis
wordpress.org/plugins/add-on-contact-form-7-mailpoetAdd a MailPoet 3 signup field to your Contact Form 7 forms.
Is Add-on Contact Form 7 – MailPoet 3 Safe to Use in 2026?
Generally Safe
Score 92/100Add-on Contact Form 7 – MailPoet 3 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of 'add-on-contact-form-7-mailpoet' v1.3.22 reveals a generally strong security posture, with no identified dangerous functions, SQL queries performed using prepared statements, no file operations, and no external HTTP requests. The absence of any known CVEs or historical vulnerabilities further strengthens this impression, suggesting a development team that is either very diligent or the plugin has not yet been a target for significant exploits. However, a critical concern arises from the complete lack of output escaping. With 51 outputs identified and none properly escaped, there is a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed back to users without proper sanitization could be exploited to inject malicious scripts, leading to session hijacking, defacement, or other harmful actions. Furthermore, the absence of nonce checks and capability checks, while not necessarily indicating a vulnerability in itself due to the zero attack surface, points to a potential gap in security best practices that could become a problem if new entry points are introduced in future versions. This lack of comprehensive security hardening, especially concerning output sanitization, significantly diminishes the plugin's otherwise positive security profile.
Key Concerns
- Unescaped output
- Missing nonce checks
- Missing capability checks
Add-on Contact Form 7 – MailPoet 3 Security Vulnerabilities
Add-on Contact Form 7 – MailPoet 3 Code Analysis
Output Escaping
Add-on Contact Form 7 – MailPoet 3 Attack Surface
WordPress Hooks 17
Maintenance & Trust
Add-on Contact Form 7 – MailPoet 3 Maintenance & Trust
Maintenance Signals
Community Trust
Add-on Contact Form 7 – MailPoet 3 Alternatives
GSheetConnector for CF7 – Connect Contact Form 7 to Google Sheets and Send Form Submissions in Real Time
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
Contact Form 7 – Success Page Redirects
contact-form-7-success-page-redirects
An add-on for Contact Form 7 that provides a straightforward method to redirect visitors to success pages or thank you pages.
Contact Form 7 Modules
contact-form-7-modules
Contact Form 7 - Add useful modules such as hidden fields and "send all fields" to the Contact Form 7 plugin
Forms: 3rd-Party Integration
forms-3rdparty-integration
Send contact form submissions from other plugins to multiple external services e.g. CRM. Configurable, custom field mapping, pre/post processing.
Autopreenchimento de endereço em formulários
cf7-cep-autofill
Preenchimento automático de campos de endereço baseado no CEP informado.
Add-on Contact Form 7 – MailPoet 3 Developer Profile
4 plugins · 7K total installs
How We Detect Add-on Contact Form 7 – MailPoet 3
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-on-contact-form-7-mailpoet/assets/css/style.css/wp-content/plugins/add-on-contact-form-7-mailpoet/assets/js/scripts.js/wp-content/plugins/add-on-contact-form-7-mailpoet/assets/js/scripts.jsadd-on-contact-form-7-mailpoet/assets/css/style.css?ver=add-on-contact-form-7-mailpoet/assets/js/scripts.js?ver=HTML / DOM Fingerprints
mailpoet-cf7-signup-fieldlistCheckboxwpcf7-mailpoetsignupmailpoet-cf7-consent-fieldmailpoet-cf7-unsubscribe-fielddata-keymailpoet_cf7_segments_dataMailPoet_CF7_Integration<label>Sign up for the newsletter</label><input type="checkbox" name="mailpoetsignup[]" value="id="mailpoetsignup"name="mailpoetsignup"