
GetResponse Forms by Optin Cat Security & Risk Analysis
wordpress.org/plugins/getresponseGetResponse Forms by Optin Cat Helps You Convert More Blog Visitors Into Subscribers. Create GetResponse Popups, Widgets & Post Boxes In Less Than …
Is GetResponse Forms by Optin Cat Safe to Use in 2026?
Generally Safe
Score 98/100GetResponse Forms by Optin Cat has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The GetResponse plugin v2.6.1 exhibits a generally strong security posture, with good practices in place like nonce checks and capability checks for its AJAX handlers. The majority of SQL queries utilize prepared statements, and output escaping is also well-implemented, minimizing common web application vulnerabilities. The absence of directly exploitable taint flows and critical/high severity CVEs in its history is a positive indicator.
However, a couple of areas warrant attention. The presence of two flows with unsanitized paths, although not classified as critical or high severity, represents a potential for unexpected behavior or information leakage if exploited. Furthermore, the plugin has a history of medium severity vulnerabilities, specifically Cross-site Scripting (XSS), suggesting that while current measures are effective, past issues indicate areas where vigilance is required. The bundled Select2 library v3.5.0 is also outdated, which could be a vector for vulnerabilities if not addressed.
Overall, the plugin is in a relatively secure state. The developers have implemented robust security mechanisms. The identified unsanitized paths and past XSS vulnerabilities are the main points of concern, though their current severity appears to be mitigated or resolved. The outdated bundled library is a minor but present risk.
Key Concerns
- Flows with unsanitized paths
- Bundled outdated library (Select2 v3.5.0)
- Medium severity vulnerabilities in history (XSS)
GetResponse Forms by Optin Cat Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
GetResponse Forms <= 2.6.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
GetResponse Forms by Optin Cat <= 2.5.7 - Reflected Cross-Site Scripting
GetResponse Forms by Optin Cat Release Timeline
GetResponse Forms by Optin Cat Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
GetResponse Forms by Optin Cat Attack Surface
AJAX Handlers 6
WordPress Hooks 55
Maintenance & Trust
GetResponse Forms by Optin Cat Maintenance & Trust
Maintenance Signals
Community Trust
GetResponse Forms by Optin Cat Alternatives
GetResponse Add-On for FormCraft
getresponse-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your GetResponse list.
Email marketing for WordPress by GetResponse Official
getresponse-official
Maximize visitor potential! Capture emails, automate marketing, track visits, and transfer ecommerce data to GetResponse for precision campaigns.
Optin Forms – Simple List Building Plugin for WordPress
optin-forms
Create beautiful optin forms with ease. Choose a form design, customize it, and add your form to your blog with a simple mouse-click.
Contact Form 7 GetResponse Extension
contact-form-7-getresponse-extension
A very easy plugin to integrate GetResponse campaigns with Contact Form 7.
AffiliateWP GetResponse Add-On
affiliatewp-getresponse-add-on
AffiliateWP GetResponse Add-on allow an Affiliate to be added to your GetResponse campaign.
GetResponse Forms by Optin Cat Developer Profile
13 plugins · 66K total installs
How We Detect GetResponse Forms by Optin Cat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/getresponse-wp/includes/classes/k/k.php/wp-content/plugins/getresponse-wp/includes/eoi-powerups.php/wp-content/plugins/getresponse-wp/includes/eoi-subscribers.php/wp-content/plugins/getresponse-wp/includes/eoi-post-types.php/wp-content/plugins/getresponse-wp/includes/eoi-layout.php/wp-content/plugins/getresponse-wp/includes/eoi-shortcode.php/wp-content/plugins/getresponse-wp/includes/eoi-widget.php/wp-content/plugins/getresponse-wp/includes/eoi-activity.php+24 moreHTML / DOM Fingerprints
fca_eoi_form<!-- The k framework -->data-fca_eoi_list_iddata-fca_eoi_thank_you_modedata-fca_eoi_thank_you_textdata-fca_eoi_iddata-fca_eoi_form_id