Kit (formerly ConvertKit) for WPForms Security & Risk Analysis

wordpress.org/plugins/integrate-convertkit-wpforms

Create Kit signup forms using WPForms

1K active installs v1.8.9 PHP 7.1+ WP 5.0+ Updated Dec 18, 2025
convertkitemailformmarketingwpforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kit (formerly ConvertKit) for WPForms Safe to Use in 2026?

Generally Safe

Score 100/100

Kit (formerly ConvertKit) for WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "integrate-convertkit-wpforms" plugin version 1.8.9 exhibits a generally strong security posture based on the provided static analysis. The absence of any reported CVEs, critical taint flows, or dangerous functions is highly encouraging. Furthermore, the plugin demonstrates good coding practices with 100% of SQL queries utilizing prepared statements and a high percentage of output being properly escaped. The presence of both nonce and capability checks indicates an awareness of common WordPress security vulnerabilities.

However, the static analysis reveals a few areas that warrant attention. While the attack surface appears minimal with no unprotected entry points, the presence of two cron events, although not explicitly detailed in terms of their security, could potentially represent hidden execution paths. The lack of any taint analysis results (0 flows analyzed) could also be a concern; it might indicate that the analysis tools were not configured to effectively trace data flows within this specific plugin, or that there are simply no complex data flows to analyze, which is unlikely for a plugin of this nature. This absence of detailed taint flow information leaves a minor gap in a comprehensive security review.

In conclusion, this plugin appears to be well-secured, with a strong emphasis on safe coding practices and a clean vulnerability history. The main area for consideration is the lack of detailed taint analysis results, which could be a reporting limitation or an indication for further deeper code review if specific concerns arise. Nevertheless, based on the available data, the plugin presents a low-risk profile.

Key Concerns

  • No detailed taint analysis data available
  • Two cron events present
Vulnerabilities
None known

Kit (formerly ConvertKit) for WPForms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kit (formerly ConvertKit) for WPForms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
52 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped56 total outputs
Attack Surface

Kit (formerly ConvertKit) for WPForms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 15
actionadmin_noticesincludes\class-integrate-convertkit-wpforms-admin-notices.php:44
filterwpforms_builder_settings_sectionsincludes\class-integrate-convertkit-wpforms-creator-network-recommendations.php:80
actionwpforms_form_settings_panel_contentincludes\class-integrate-convertkit-wpforms-creator-network-recommendations.php:81
filterwpforms_save_form_argsincludes\class-integrate-convertkit-wpforms-creator-network-recommendations.php:82
actionwpforms_save_formincludes\class-integrate-convertkit-wpforms-creator-network-recommendations.php:83
actionwpforms_frontend_jsincludes\class-integrate-convertkit-wpforms-creator-network-recommendations.php:84
actioninitincludes\class-integrate-convertkit-wpforms.php:62
actioninitincludes\class-integrate-convertkit-wpforms.php:65
actioninitincludes\class-integrate-convertkit-wpforms.php:66
actionwpforms_settings_enqueueincludes\class-integrate-convertkit-wpforms.php:68
actionwpforms_builder_enqueuesincludes\class-integrate-convertkit-wpforms.php:69
actionintegrate_convertkit_wpforms_refresh_tokenincludes\cron-functions.php:53
actionconvertkit_api_refresh_tokenincludes\functions.php:152
actionconvertkit_api_access_token_invalidincludes\functions.php:156
actionwpforms_loadedintegrate-convertkit-wpforms.php:73

Scheduled Events 2

integrate_convertkit_wpforms_refresh_token
integrate_convertkit_wpforms_refresh_token
Maintenance & Trust

Kit (formerly ConvertKit) for WPForms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 18, 2025
PHP min version7.1
Downloads61K

Community Trust

Rating100/100
Number of ratings3
Active installs1K
Developer Profile

Kit (formerly ConvertKit) for WPForms Developer Profile

Bill Erickson

2 plugins · 81K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kit (formerly ConvertKit) for WPForms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integrate-convertkit-wpforms/assets/css/creator-network-recommendations.css/wp-content/plugins/integrate-convertkit-wpforms/assets/js/creator-network-recommendations.js/wp-content/plugins/integrate-convertkit-wpforms/assets/js/convertkit-wpforms.js
Script Paths
/wp-content/plugins/integrate-convertkit-wpforms/assets/js/creator-network-recommendations.js/wp-content/plugins/integrate-convertkit-wpforms/assets/js/convertkit-wpforms.js
Version Parameters
integrate-convertkit-wpforms/assets/css/creator-network-recommendations.css?ver=integrate-convertkit-wpforms/assets/js/creator-network-recommendations.js?ver=integrate-convertkit-wpforms/assets/js/convertkit-wpforms.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpforms-panel-content-section-convertkit
HTML Comments
<!-- Kit (formerly ConvertKit) for WPForms Plugin. -->
Data Attributes
data-convertkit-form-iddata-convertkit-connection-iddata-convertkit-creator-network-recommendations-script
JS Globals
ConvertKit_WPForms_Creator_Network_Recommendations
FAQ

Frequently Asked Questions about Kit (formerly ConvertKit) for WPForms