
Icegram Collect – Easy Form, Lead Collection and Subscription plugin Security & Risk Analysis
wordpress.org/plugins/icegram-rainmakerGet readymade contact forms, email subscription forms and custom forms for your website. Choose from beautiful templates and get started within second …
Is Icegram Collect – Easy Form, Lead Collection and Subscription plugin Safe to Use in 2026?
Generally Safe
Score 97/100Icegram Collect – Easy Form, Lead Collection and Subscription plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The "icegram-rainmaker" plugin, version 1.3.20, exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and implementing nonce checks for all AJAX handlers, significant concerns remain. The presence of 3 AJAX handlers without authentication checks represents a considerable attack surface, potentially allowing unauthorized actions. Furthermore, a substantial 39% of output escaping indicates a risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data might not be properly sanitized before being displayed to users. The vulnerability history reveals a pattern of medium severity issues, specifically Missing Authorization and Cross-Site Scripting, suggesting a recurring need for more robust input validation and authorization enforcement. While there are no currently unpatched CVEs, the past prevalence of these vulnerability types warrants careful attention.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of output escaping
- History of medium severity vulnerabilities
Icegram Collect – Easy Form, Lead Collection and Subscription plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Icegram Collect – Easy Form, Lead Collection and Subscription plugin <= 1.3.18 - Missing Authorization
Icegram Collect – Easy Form, Lead Collection and Subscription plugin <= 1.3.14 - Missing Authorization
Icegram Collect <= 1.3.8 - Authenticated(Contributor+) Cross-Site Scripting via Shortcode
Icegram Collect – Easy Form, Lead Collection and Subscription plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Icegram Collect – Easy Form, Lead Collection and Subscription plugin Attack Surface
AJAX Handlers 16
Shortcodes 1
WordPress Hooks 66
Maintenance & Trust
Icegram Collect – Easy Form, Lead Collection and Subscription plugin Maintenance & Trust
Maintenance Signals
Community Trust
Icegram Collect – Easy Form, Lead Collection and Subscription plugin Alternatives
Integration for Mailchimp – Contact Form 7, WPForms, Elementor, Gravity Forms and More
integrate-with-mailchimp
Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with Mailchimp.
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR)
contact-form-7-image-captcha
Adds an Image CAPTCHA to Contact Form 7 and WPForms, GDPR ready, perfect WPForms or Contact Form 7 Spam Protection Image CAPTCHA, adds a honeypot
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
Connect Contact Form 7 and Mailchimp
contact-form-7-mailchimp-extension
Connect Contact Form 7 to Mailchimp. Automatically sync form submissions to your Mailchimp audiences with merge field mapping, double opt-in, and opt- …
Icegram Collect – Easy Form, Lead Collection and Subscription plugin Developer Profile
8 plugins · 84K total installs
How We Detect Icegram Collect – Easy Form, Lead Collection and Subscription plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/icegram-rainmaker/lite/css/rm-admin-style.css/wp-content/plugins/icegram-rainmaker/lite/css/rm-frontend-style.css/wp-content/plugins/icegram-rainmaker/lite/js/rm-admin-script.js/wp-content/plugins/icegram-rainmaker/lite/js/rm-frontend-script.js/wp-content/plugins/icegram-rainmaker/lite/js/rm-admin-script.js/wp-content/plugins/icegram-rainmaker/lite/js/rm-frontend-script.jsicegram-rainmaker/lite/css/rm-admin-style.css?ver=icegram-rainmaker/lite/css/rm-frontend-style.css?ver=icegram-rainmaker/lite/js/rm-admin-script.js?ver=icegram-rainmaker/lite/js/rm-frontend-script.js?ver=HTML / DOM Fingerprints
ig-rm-form-wrapperrm-modal-contentrm-form-fieldrm-modal-overlay<!-- Icegram Rainmaker --><!-- Icegram Rainmaker Form Wrapper --><!-- Icegram Rainmaker Modal Overlay --><!-- Icegram Rainmaker Modal Content -->+1 moredata-rm-modal-iddata-rm-form-idwindow.ig_rm_ajax_objectvar ig_rm_params/wp-json/icegram-rainmaker/v1/submit-form[icegram_rainmaker_form id='']