
Gutenberg Forms Add-on for MailPoet Security & Risk Analysis
wordpress.org/plugins/guten-forms-mailpoetMailPoet add-on for Gutenberg Forms. Connect with MailPoet and send leads/subscribers to your MailPoet list with the form submissions.
Is Gutenberg Forms Add-on for MailPoet Safe to Use in 2026?
Generally Safe
Score 85/100Gutenberg Forms Add-on for MailPoet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the plugin 'guten-forms-mailpoet' v2.1.1 exhibits a strong security posture in several key areas. The absence of any identified CVEs, coupled with a clean vulnerability history, suggests a well-maintained and secure codebase. Furthermore, the static analysis reveals no dangerous functions, no raw SQL queries, and all output is properly escaped, indicating robust coding practices against common web vulnerabilities. The plugin also successfully avoids external HTTP requests, which can sometimes be an attack vector.
However, there are some areas that warrant attention, despite not resulting in explicit critical findings in this analysis. The complete lack of nonce checks and capability checks across all identified entry points (though there are none reported) is a potential concern. If any new entry points were to be introduced in future versions without these checks, it could expose the plugin to significant risks like Cross-Site Request Forgery (CSRF) or unauthorized actions by unprivileged users. The single file operation, while not inherently risky, is worth monitoring to ensure it's handled securely and doesn't become an avenue for unauthorized file access or manipulation.
In conclusion, the plugin demonstrates a commendable commitment to security through its clean vulnerability history and avoidance of common risky coding patterns like raw SQL and unescaped output. The most significant area for improvement and continued vigilance lies in the implementation of authentication and authorization mechanisms for any future additions to its attack surface. The current lack of identified vulnerabilities is a positive sign, but the absence of protective checks on potential, albeit currently non-existent, entry points represents a latent risk.
Key Concerns
- No nonce checks on potential entry points
- No capability checks on potential entry points
- One file operation without specific context
Gutenberg Forms Add-on for MailPoet Security Vulnerabilities
Gutenberg Forms Add-on for MailPoet Code Analysis
Gutenberg Forms Add-on for MailPoet Attack Surface
WordPress Hooks 3
Maintenance & Trust
Gutenberg Forms Add-on for MailPoet Maintenance & Trust
Maintenance Signals
Community Trust
Gutenberg Forms Add-on for MailPoet Alternatives
Gutenberg Forms Add-on for Akismet
guten-forms-akismet
Akismet add-on for Gutenberg Forms. Connect with Akismet and protect your form submissions against spam via their global database of spam.
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
forminator
Best WordPress form builder plugin. Create contact forms, payment forms & order forms with 1000+ integrations.
Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform
embed-form
Create and embed secure online forms in WordPress using Jotform’s drag-and-drop builder, with PCI and HIPAA compliance and full data-security support.
Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder
gutena-forms
WordPress form builder to create lightweight contact forms, survey forms, feedback forms, booking forms, etc., right inside the Gutenberg editor.
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms
happyforms
Best WordPress contact form, newsletter form and payment form builder without the sucky stuff — lost emails, pesky spam, leaky privacy and outsourced …
Gutenberg Forms Add-on for MailPoet Developer Profile
3 plugins · 1K total installs
How We Detect Gutenberg Forms Add-on for MailPoet
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/guten-forms-mailpoet/assets/css/guten-forms-mailpoet-styles.css/wp-content/plugins/guten-forms-mailpoet/assets/js/guten-forms-mailpoet-admin-scripts.js/wp-content/plugins/guten-forms-mailpoet/assets/js/guten-forms-mailpoet-scripts.js/wp-content/plugins/guten-forms-mailpoet/assets/js/guten-forms-mailpoet-admin-scripts.js/wp-content/plugins/guten-forms-mailpoet/assets/js/guten-forms-mailpoet-scripts.jsguten-forms-mailpoet/assets/css/guten-forms-mailpoet-styles.css?ver=guten-forms-mailpoet/assets/js/guten-forms-mailpoet-admin-scripts.js?ver=guten-forms-mailpoet/assets/js/guten-forms-mailpoet-scripts.js?ver=HTML / DOM Fingerprints
guten-forms-mailpoet-settings-pagegutenbergFormsMailPoetAdmingutenbergFormsMailPoet/wp-json/guten-forms-mailpoet/v1