GetResponse Forms by Optin Cat Security & Risk Analysis

wordpress.org/plugins/getresponse

GetResponse Forms by Optin Cat Helps You Convert More Blog Visitors Into Subscribers. Create GetResponse Popups, Widgets & Post Boxes In Less Than …

1K active installs v2.6.2 PHP + WP 3.9.1+ Updated Apr 11, 2026
getresponsegetresponse-blockgetresponse-formgetresponse-widgetgetresponse-wordpress
98
A · Safe
CVEs total2
Unpatched0
Last CVESep 22, 2025
Safety Verdict

Is GetResponse Forms by Optin Cat Safe to Use in 2026?

Generally Safe

Score 98/100

GetResponse Forms by Optin Cat has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Sep 22, 2025Updated 1mo ago
Risk Assessment

The GetResponse plugin v2.6.1 exhibits a generally strong security posture, with good practices in place like nonce checks and capability checks for its AJAX handlers. The majority of SQL queries utilize prepared statements, and output escaping is also well-implemented, minimizing common web application vulnerabilities. The absence of directly exploitable taint flows and critical/high severity CVEs in its history is a positive indicator.

However, a couple of areas warrant attention. The presence of two flows with unsanitized paths, although not classified as critical or high severity, represents a potential for unexpected behavior or information leakage if exploited. Furthermore, the plugin has a history of medium severity vulnerabilities, specifically Cross-site Scripting (XSS), suggesting that while current measures are effective, past issues indicate areas where vigilance is required. The bundled Select2 library v3.5.0 is also outdated, which could be a vector for vulnerabilities if not addressed.

Overall, the plugin is in a relatively secure state. The developers have implemented robust security mechanisms. The identified unsanitized paths and past XSS vulnerabilities are the main points of concern, though their current severity appears to be mitigated or resolved. The outdated bundled library is a minor but present risk.

Key Concerns

  • Flows with unsanitized paths
  • Bundled outdated library (Select2 v3.5.0)
  • Medium severity vulnerabilities in history (XSS)
Vulnerabilities
2 published

GetResponse Forms by Optin Cat Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-59549medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

GetResponse Forms <= 2.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 22, 2025 Patched in 2.6.1 (5d)
CVE-2024-8740medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

GetResponse Forms by Optin Cat <= 2.5.7 - Reflected Cross-Site Scripting

Oct 17, 2024 Patched in 2.5.8 (47d)
Code Analysis
Analyzed Mar 16, 2026

GetResponse Forms by Optin Cat Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
8 prepared
Unescaped Output
11
154 escaped
Nonce Checks
8
Capability Checks
7
File Operations
6
External Requests
5
Bundled Libraries
1

Bundled Libraries

Select23.5.0

SQL Query Safety

80% prepared10 total queries

Output Escaping

93% escaped165 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
<eoi-post-types> (includes\eoi-post-types.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GetResponse Forms by Optin Cat Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_fca_eoi_activityincludes\eoi-activity.php:44
noprivwp_ajax_fca_eoi_activityincludes\eoi-activity.php:45
authwp_ajax_fca_eoi_subscribeincludes\eoi-post-types.php:53
noprivwp_ajax_fca_eoi_subscribeincludes\eoi-post-types.php:54
authwp_ajax_fca_eoi_dismissincludes\eoi-post-types.php:56
authwp_ajax_fca_eoi_uninstallincludes\eoi-uninstall.php:74
WordPress Hooks 55
filterpre_set_site_transient_update_pluginsincludes\classes\edd_sl\EDD_SL_Plugin_Updater.php:75
filterplugins_apiincludes\classes\edd_sl\EDD_SL_Plugin_Updater.php:76
actionafter_plugin_rowincludes\classes\edd_sl\EDD_SL_Plugin_Updater.php:77
actionadmin_initincludes\classes\edd_sl\EDD_SL_Plugin_Updater.php:78
actionin_admin_footerincludes\classes\k\k.php:563
actioninitincludes\eoi-block.php:48
actionenqueue_block_editor_assetsincludes\eoi-block.php:99
actionwp_dashboard_setupincludes\eoi-functions.php:18
filtertiny_mce_before_initincludes\eoi-functions.php:234
actioninitincludes\eoi-post-types.php:21
filtermanage_easy-opt-ins_posts_columnsincludes\eoi-post-types.php:22
actionmanage_easy-opt-ins_posts_custom_columnincludes\eoi-post-types.php:23
filterpost_row_actionsincludes\eoi-post-types.php:24
actionadmin_post_fca_eoi_reset_statsincludes\eoi-post-types.php:27
actionwp_dashboard_setupincludes\eoi-post-types.php:30
actionsave_postincludes\eoi-post-types.php:33
filterthe_contentincludes\eoi-post-types.php:36
actionadmin_enqueue_scriptsincludes\eoi-post-types.php:39
actionadmin_headincludes\eoi-post-types.php:41
actionadmin_noticesincludes\eoi-post-types.php:43
actionadmin_noticesincludes\eoi-post-types.php:46
filteradmin_body_classincludes\eoi-post-types.php:49
filterwp_insert_post_dataincludes\eoi-post-types.php:51
filterget_user_option_screen_layout_easy-opt-insincludes\eoi-post-types.php:58
filterget_user_option_meta-box-order_easy-opt-insincludes\eoi-post-types.php:60
filterpost_updated_messagesincludes\eoi-post-types.php:62
filterbulk_actions-edit-easy-opt-insincludes\eoi-post-types.php:64
filterpost_row_actionsincludes\eoi-post-types.php:66
actionadmin_noticesincludes\eoi-post-types.php:68
filterenter_title_hereincludes\eoi-post-types.php:70
filterinitincludes\eoi-post-types.php:72
filterthe_contentincludes\eoi-post-types.php:79
actionwp_headincludes\eoi-post-types.php:81
actionwp_footerincludes\eoi-post-types.php:82
filterwp_footerincludes\eoi-post-types.php:85
filterfca_eoi_alter_admin_noticesincludes\eoi-post-types.php:93
actionwpincludes\eoi-post-types.php:2164
actionadmin_menuincludes\eoi-powerups.php:22
actionadmin_initincludes\eoi-powerups.php:55
filterfca_eoi_setting_filterincludes\eoi-subscribers.php:27
actionfca_eoi_after_submissionincludes\eoi-subscribers.php:171
actionadmin_menuincludes\eoi-subscribers.php:172
actionplugins_loadedincludes\eoi-subscribers.php:173
filterwp_privacy_personal_data_exportersincludes\eoi-subscribers.php:174
filterwp_privacy_personal_data_erasersincludes\eoi-subscribers.php:175
actionadmin_enqueue_scriptsincludes\eoi-uninstall.php:40
actionadmin_menuincludes\eoi-upgrade.php:57
actionadmin_footerincludes\eoi-upgrade.php:58
filteradmin_footer_textincludes\eoi-upgrade.php:59
actionadmin_noticesincludes\eoi-upgrade.php:60
actionwidgets_initincludes\eoi-widget.php:12
filterfca_eoi_setting_filterpowerups\2_custom_css\powerup.php:11
actionfca_eoi_powerupspowerups\2_custom_css\powerup.php:22
actionadmin_enqueue_scriptspowerups\2_custom_css\powerup.php:23
filterfca_eoi_alter_formpowerups\2_custom_css\powerup.php:24
Maintenance & Trust

GetResponse Forms by Optin Cat Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedApr 11, 2026
PHP min version
Downloads82K

Community Trust

Rating98/100
Number of ratings9
Active installs1K
Developer Profile

GetResponse Forms by Optin Cat Developer Profile

fatcatapps

13 plugins · 66K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
250 days
View full developer profile
Detection Fingerprints

How We Detect GetResponse Forms by Optin Cat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/getresponse-wp/includes/classes/k/k.php/wp-content/plugins/getresponse-wp/includes/eoi-powerups.php/wp-content/plugins/getresponse-wp/includes/eoi-subscribers.php/wp-content/plugins/getresponse-wp/includes/eoi-post-types.php/wp-content/plugins/getresponse-wp/includes/eoi-layout.php/wp-content/plugins/getresponse-wp/includes/eoi-shortcode.php/wp-content/plugins/getresponse-wp/includes/eoi-widget.php/wp-content/plugins/getresponse-wp/includes/eoi-activity.php+24 more

HTML / DOM Fingerprints

CSS Classes
fca_eoi_form
HTML Comments
<!-- The k framework -->
Data Attributes
data-fca_eoi_list_iddata-fca_eoi_thank_you_modedata-fca_eoi_thank_you_textdata-fca_eoi_iddata-fca_eoi_form_id
FAQ

Frequently Asked Questions about GetResponse Forms by Optin Cat