Gutenberg Forms Add-on for MailPoet Security & Risk Analysis

wordpress.org/plugins/guten-forms-mailpoet

MailPoet add-on for Gutenberg Forms. Connect with MailPoet and send leads/subscribers to your MailPoet list with the form submissions.

100 active installs v2.1.1 PHP + WP 5.0+ Updated May 18, 2022
contact-formgutenberg-blockgutenberg-formmailpoetwordpress-form
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Gutenberg Forms Add-on for MailPoet Safe to Use in 2026?

Generally Safe

Score 85/100

Gutenberg Forms Add-on for MailPoet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the plugin 'guten-forms-mailpoet' v2.1.1 exhibits a strong security posture in several key areas. The absence of any identified CVEs, coupled with a clean vulnerability history, suggests a well-maintained and secure codebase. Furthermore, the static analysis reveals no dangerous functions, no raw SQL queries, and all output is properly escaped, indicating robust coding practices against common web vulnerabilities. The plugin also successfully avoids external HTTP requests, which can sometimes be an attack vector.

However, there are some areas that warrant attention, despite not resulting in explicit critical findings in this analysis. The complete lack of nonce checks and capability checks across all identified entry points (though there are none reported) is a potential concern. If any new entry points were to be introduced in future versions without these checks, it could expose the plugin to significant risks like Cross-Site Request Forgery (CSRF) or unauthorized actions by unprivileged users. The single file operation, while not inherently risky, is worth monitoring to ensure it's handled securely and doesn't become an avenue for unauthorized file access or manipulation.

In conclusion, the plugin demonstrates a commendable commitment to security through its clean vulnerability history and avoidance of common risky coding patterns like raw SQL and unescaped output. The most significant area for improvement and continued vigilance lies in the implementation of authentication and authorization mechanisms for any future additions to its attack surface. The current lack of identified vulnerabilities is a positive sign, but the absence of protective checks on potential, albeit currently non-existent, entry points represents a latent risk.

Key Concerns

  • No nonce checks on potential entry points
  • No capability checks on potential entry points
  • One file operation without specific context
Vulnerabilities
None known

Gutenberg Forms Add-on for MailPoet Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Gutenberg Forms Add-on for MailPoet Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0
Attack Surface

Gutenberg Forms Add-on for MailPoet Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtergutenberg_forms_integrationsaddon.php:6
actiongutenberg_forms_submission__mailpoetaddon.php:65
actionadmin_initinit.php:26
Maintenance & Trust

Gutenberg Forms Add-on for MailPoet Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMay 18, 2022
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Gutenberg Forms Add-on for MailPoet Developer Profile

Jack K

3 plugins · 1K total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Gutenberg Forms Add-on for MailPoet

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/guten-forms-mailpoet/assets/css/guten-forms-mailpoet-styles.css/wp-content/plugins/guten-forms-mailpoet/assets/js/guten-forms-mailpoet-admin-scripts.js/wp-content/plugins/guten-forms-mailpoet/assets/js/guten-forms-mailpoet-scripts.js
Script Paths
/wp-content/plugins/guten-forms-mailpoet/assets/js/guten-forms-mailpoet-admin-scripts.js/wp-content/plugins/guten-forms-mailpoet/assets/js/guten-forms-mailpoet-scripts.js
Version Parameters
guten-forms-mailpoet/assets/css/guten-forms-mailpoet-styles.css?ver=guten-forms-mailpoet/assets/js/guten-forms-mailpoet-admin-scripts.js?ver=guten-forms-mailpoet/assets/js/guten-forms-mailpoet-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
guten-forms-mailpoet-settings-page
JS Globals
gutenbergFormsMailPoetAdmingutenbergFormsMailPoet
REST Endpoints
/wp-json/guten-forms-mailpoet/v1
FAQ

Frequently Asked Questions about Gutenberg Forms Add-on for MailPoet