
Campaign Monitor Add-On for FormCraft Security & Risk Analysis
wordpress.org/plugins/campaign-monitor-for-formcraftCreate gorgeous optin forms for your site with FormCraft, and grow your Campaign Monitor list.
Is Campaign Monitor Add-On for FormCraft Safe to Use in 2026?
Generally Safe
Score 85/100Campaign Monitor Add-On for FormCraft has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'campaign-monitor-for-formcraft' v1.2 plugin exhibits a concerning security posture primarily due to a significant lack of authentication and authorization checks on its entry points. With three AJAX handlers identified and none protected by authentication mechanisms, any unauthenticated user can potentially trigger these functions. This creates a substantial attack surface, even without any known critical vulnerabilities from static analysis or historical data.
While the plugin demonstrates good practices by using prepared statements for all its SQL queries and appears to have no recorded vulnerabilities in its history, these strengths are heavily overshadowed by the identified security flaws. The absence of nonce checks and capability checks on AJAX actions, coupled with the fact that 0% of its outputs are properly escaped, indicates a high risk of Cross-Site Scripting (XSS) and other injection attacks. The plugin's limited attack surface (only AJAX handlers) is a minor mitigating factor, but the lack of protection on these handlers makes them prime targets. The absence of taint analysis findings suggests that current static analysis tools didn't find any obvious critical flows, but this is less reassuring given the other identified weaknesses.
In conclusion, despite a clean vulnerability history and secure SQL practices, the 'campaign-monitor-for-formcraft' v1.2 plugin is rated as high risk. The critical oversight in securing its AJAX handlers presents a clear and present danger of unauthorized execution and potential data compromise. The lack of output escaping further amplifies the XSS risk. Remediation should focus on implementing robust authentication and authorization for all AJAX actions and ensuring proper output sanitization.
Key Concerns
- AJAX handlers without auth checks
- Outputs not properly escaped
- Nonce checks missing
- Capability checks missing
Campaign Monitor Add-On for FormCraft Security Vulnerabilities
Campaign Monitor Add-On for FormCraft Code Analysis
Output Escaping
Campaign Monitor Add-On for FormCraft Attack Surface
AJAX Handlers 3
WordPress Hooks 3
Maintenance & Trust
Campaign Monitor Add-On for FormCraft Maintenance & Trust
Maintenance Signals
Community Trust
Campaign Monitor Add-On for FormCraft Alternatives
MailChimp Add-On for FormCraft
mailchimp-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your MailChimp list.
GetResponse Add-On for FormCraft
getresponse-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your GetResponse list.
MailPoet Add-On for FormCraft
mailpoet-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your MailPoet list.
Ultra Addons for Contact Form 7
ultimate-addons-for-contact-form-7
50+ Essential Addons for Contact Form 7 - Conditional Fields, Multi Step, Redirection, Columns, WooCommerce, Mailchimp & more
Lead Form Builder & Contact Form
lead-form-builder
Fast Drag & Drop Contact From Builder and Lead Generation Tool With Google One Tap Login. Supports Block Editor.
Campaign Monitor Add-On for FormCraft Developer Profile
8 plugins · 11K total installs
How We Detect Campaign Monitor Add-On for FormCraft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/campaign-monitor-for-formcraft/assets/builder.css/wp-content/plugins/campaign-monitor-for-formcraft/assets/builder.jsassets/builder.jsHTML / DOM Fingerprints
cm-coverapi-keyhide-{{Addons.Campaign.showOptions}}IsRedBorderformcraft-loadernos-{{Addons.Campaign.Map.length}}nothing-heresomething-here+4 moreng-modelng-clickng-showng-repeatng-optionsformcraft_campaign_triggerformcraft_campaign_addonformcraft_campaign_scriptsformcraft_campaign_test_apiformcraft_campaign_get_listsformcraft_campaign_get_columns+6 more/wp-admin/admin-ajax.php?action=formcraft_campaign_test_api/wp-admin/admin-ajax.php?action=formcraft_campaign_get_lists/wp-admin/admin-ajax.php?action=formcraft_campaign_get_columns<div id='cm-cover'<div class='help-link'><div class='api-key hide-{{Addons.Campaign.showOptions}}'><input placeholder='