
Enormail Sign Up Forms Security & Risk Analysis
wordpress.org/plugins/enormail-sign-up-formsAdd an Enormail signup form to your Wordpress website and start growing your list.
Is Enormail Sign Up Forms Safe to Use in 2026?
Generally Safe
Score 92/100Enormail Sign Up Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The enormail-sign-up-forms plugin v1.2.0 presents a concerning security posture primarily due to its unprotected entry points. While the plugin demonstrates some good practices, such as a high percentage of SQL queries using prepared statements and a decent number of capability checks, the presence of two AJAX handlers without any authentication checks represents a significant risk. Furthermore, the taint analysis reveals three high-severity flows with unsanitized paths, indicating potential for cross-site scripting (XSS) or other injection vulnerabilities if input from these flows is not properly sanitized before use.
The plugin's vulnerability history is currently clean, with no recorded CVEs. This is a positive indicator, suggesting the developers may have a good understanding of secure coding. However, the absence of past vulnerabilities does not negate the risks identified in the static analysis. The clean history could be a result of limited usage, lack of public auditing, or simply good fortune. The presence of unsanitized taint flows is a red flag that requires immediate attention, regardless of past history.
In conclusion, while the plugin has some strengths in its SQL handling and capability checks, the critical weakness lies in its unprotected AJAX endpoints and high-severity unsanitized taint flows. These issues create a notable attack surface that could be exploited. Addressing the unsanitized taint flows and implementing proper authentication on AJAX handlers are paramount to improving the plugin's security.
Key Concerns
- Unprotected AJAX handlers (2)
- High severity taint flows (3)
- Low proper output escaping (32%)
Enormail Sign Up Forms Security Vulnerabilities
Enormail Sign Up Forms Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Enormail Sign Up Forms Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
Enormail Sign Up Forms Maintenance & Trust
Maintenance Signals
Community Trust
Enormail Sign Up Forms Alternatives
MailerLite – Signup forms (official)
official-mailerlite-sign-up-forms
Add newsletter signup forms to your WordPress site. Subscribers will be saved directly to your MailerLite account. Super easy to set up!
EmailSystem
emailsystem
Use a Drag and Drop Form Builder to create Subscription Forms for the EmailSystem email marketing platform.
MC4WP: Mailchimp for WordPress
mailchimp-for-wp
The #1 Mailchimp plugin for WordPress. Allows you to add a multitude of newsletter sign-up methods to your site.
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
MailMunch – Grow your Email List
mailmunch
The best free plugin to get more email subscribers. Beautiful opt-in forms that integrate with MailChimp, Constant Contact, AWeber, Campaign Monitor a …
Enormail Sign Up Forms Developer Profile
1 plugin · 400 total installs
How We Detect Enormail Sign Up Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/enormail-sign-up-forms/admin/css/enormail-admin.css/wp-content/plugins/enormail-sign-up-forms/admin/js/enormail-admin.jsenormail-admin.css?ver=enormail-admin.js?ver=HTML / DOM Fingerprints
enormail-form-container<!-- Enormail Sign Up Form -->data-enormail-form-idwindow.enormailConfig[enormail_form