Integrate Ecomail and Elementor Forms Security & Risk Analysis

wordpress.org/plugins/ecomail-elementor-form-integration

Integrate Ecomail and Elementor Forms je plugin, který umožňuje integraci formulářů vytvořených v nástroji Elementor PRO s e-mailovým marketingovým ná …

700 active installs v1.3.1 PHP + WP 5.2+ Updated Jul 1, 2024
ecomailelementorelementor-proformintegration
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Integrate Ecomail and Elementor Forms Safe to Use in 2026?

Generally Safe

Score 92/100

Integrate Ecomail and Elementor Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'ecomail-elementor-form-integration' v1.3.1 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, all SQL queries utilizing prepared statements, and 100% output escaping are excellent indicators of secure coding practices. Furthermore, the lack of any recorded vulnerabilities in its history is a positive sign. The presence of a single external HTTP request is noted, but without further context, its security implications are minimal, assuming it's for a legitimate service integration and properly handled.

However, the analysis does reveal some areas for potential concern, primarily related to the attack surface and capability checks. The plugin reports zero entry points, which is exceptionally low and potentially indicates a very limited scope of functionality or that the analysis might have missed certain integration points. More importantly, the complete absence of nonce checks and capability checks across all entry points (even if there are zero reported) is a significant weakness. While the current static analysis shows no direct exploitable paths, relying on no authorization checks makes the plugin vulnerable to privilege escalation or unauthorized actions if any new entry points are introduced or if the analysis missed existing ones that could be triggered by unauthenticated users.

In conclusion, while the plugin demonstrates good core development practices regarding data handling and output, the lack of any authorization and input validation mechanisms (nonces, capabilities) represents a critical underlying risk. If any functionality were to become exposed or accessible, it could be exploited without proper authentication. The extremely low attack surface, if accurate, mitigates this risk considerably for the current version, but it is a latent vulnerability that should be addressed for future development.

Key Concerns

  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Integrate Ecomail and Elementor Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Integrate Ecomail and Elementor Forms Release Timeline

v1.3.1Current
v1.3.0
v1.2.1
v1.2.0
v1.1.1
Code Analysis
Analyzed Mar 16, 2026

Integrate Ecomail and Elementor Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0
Attack Surface

Integrate Ecomail and Elementor Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionelementor_pro/initform-actions\ecomail.php:295
actionelementor_pro/forms/actions/registerintegrate-ecomail-elementor.php:35
Maintenance & Trust

Integrate Ecomail and Elementor Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJul 1, 2024
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs700
Developer Profile

Integrate Ecomail and Elementor Forms Developer Profile

Adam Kotala

1 plugin · 700 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Integrate Ecomail and Elementor Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ecomail-elementor-form-integration/assets/css/ecomail-elementor-form-integration.css/wp-content/plugins/ecomail-elementor-form-integration/assets/js/ecomail-elementor-form-integration.js
Script Paths
/wp-content/plugins/ecomail-elementor-form-integration/assets/js/ecomail-elementor-form-integration.js
Version Parameters
ecomail-elementor-form-integration/assets/css/ecomail-elementor-form-integration.css?ver=ecomail-elementor-form-integration/assets/js/ecomail-elementor-form-integration.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Integrate Ecomail and Elementor Forms