Instapage Plugin Security & Risk Analysis

wordpress.org/plugins/instapage

Instapage plugin - the best way for WordPress to seamlessly publish landing pages as a natural extension of your WordPress blog or website.

5K active installs v3.7.1 PHP 5.4.0+ WP 3.4+ Updated Dec 3, 2025
a-b-testinginstapagelanding-pagelead-generationsqueeze-page
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 26, 2025
Safety Verdict

Is Instapage Plugin Safe to Use in 2026?

Generally Safe

Score 99/100

Instapage Plugin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Sep 26, 2025Updated 5mo ago
Risk Assessment

The Instapage plugin v3.7.1 exhibits a mixed security posture. While it demonstrates good practices in its handling of SQL queries, with 91% using prepared statements, and avoids dangerous functions and file operations, significant concerns arise from its attack surface. Two AJAX handlers are present, and critically, both lack authentication checks, creating a direct entry point for potential unauthorized actions. The output escaping is also alarmingly low, with only 2% of outputs being properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin has a history of one medium-severity CVE, which was Cross-Site Request Forgery (CSRF), suggesting past vulnerabilities have been addressed. However, the lack of proper authentication on AJAX handlers, combined with poor output escaping, presents immediate and pressing risks that outweigh the positive aspects of its SQL handling and vulnerability history, which indicates a proactive approach to patching.

Key Concerns

  • Unprotected AJAX handlers
  • Low output escaping coverage
  • Bundled library (Select2)
Vulnerabilities
1 published

Instapage Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-60115medium · 4.3Cross-Site Request Forgery (CSRF)

Instapage Plugin <= 3.7.0 - Cross-Site Request Forgery

Sep 26, 2025 Patched in 3.7.1 (70d)
Version History

Instapage Plugin Release Timeline

v3.7.1Current
v3.7.01 CVE
v3.6.01 CVE
v3.5.121 CVE
v3.5.111 CVE
v3.5.101 CVE
v3.5.91 CVE
v3.5.81 CVE
v3.5.71 CVE
v3.5.61 CVE
v3.5.51 CVE
v3.5.41 CVE
v3.5.31 CVE
v3.5.21 CVE
v3.5.11 CVE
v3.5.01 CVE
v3.4.31 CVE
v3.4.21 CVE
v3.4.11 CVE
v3.4.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Instapage Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
29 prepared
Unescaped Output
158
4 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

91% prepared32 total queries

Output Escaping

2% escaped162 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
httpResponseCode (InstapageCmsPluginHelper.php:452)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Instapage Plugin Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_instapage_ajax_callconnectors\InstapageCmsPluginWPConnector.php:399
noprivwp_ajax_instapage_ajax_callconnectors\InstapageCmsPluginWPConnector.php:400
WordPress Hooks 8
actionadmin_enqueue_scriptsconnectors\InstapageCmsPluginWPConnector.php:392
actionadmin_enqueue_scriptsconnectors\InstapageCmsPluginWPConnector.php:393
actionadmin_menuconnectors\InstapageCmsPluginWPConnector.php:397
actioninitconnectors\InstapageCmsPluginWPConnector.php:401
actionwpconnectors\InstapageCmsPluginWPConnector.php:402
actionwpconnectors\InstapageCmsPluginWPConnector.php:403
actiontemplate_redirectconnectors\InstapageCmsPluginWPConnector.php:404
filterhttps_ssl_verifyconnectors\InstapageCmsPluginWPConnector.php:406
Maintenance & Trust

Instapage Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 3, 2025
PHP min version5.4.0
Downloads507K

Community Trust

Rating96/100
Number of ratings218
Active installs5K
Developer Profile

Instapage Plugin Developer Profile

instapagedev

1 plugin · 5K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
70 days
View full developer profile
Detection Fingerprints

How We Detect Instapage Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/instapage/css//wp-content/plugins/instapage/js//wp-content/plugins/instapage/images//wp-content/plugins/instapage/assets/
Script Paths
instapage/js/instapage-plugins.jsinstapage/js/instapage-preview.jsinstapage/js/instapage-app.js
Version Parameters
instapage/css/style.css?ver=instapage/js/instapage-app.js?ver=instapage/js/instapage-plugins.js?ver=

HTML / DOM Fingerprints

CSS Classes
instapage-editor-containerinstapage-editor-wrapperinstapage-preview-iframe
HTML Comments
<!-- Instapage Plugin --><!-- Instapage Content -->
Data Attributes
data-instapage-editordata-instapage-previewdata-instapage-page-id
JS Globals
InstapageAppInstapagePreviewInstapagePlugins
REST Endpoints
/wp-json/instapage/v1/pages/wp-json/instapage/v1/settings/wp-json/instapage/v1/publish
Shortcode Output
[instapage-embed]
FAQ

Frequently Asked Questions about Instapage Plugin