
Kit (formerly ConvertKit) for WPForms Security & Risk Analysis
wordpress.org/plugins/integrate-convertkit-wpformsCreate Kit signup forms using WPForms
Is Kit (formerly ConvertKit) for WPForms Safe to Use in 2026?
Generally Safe
Score 100/100Kit (formerly ConvertKit) for WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "integrate-convertkit-wpforms" plugin version 1.8.9 exhibits a generally strong security posture based on the provided static analysis. The absence of any reported CVEs, critical taint flows, or dangerous functions is highly encouraging. Furthermore, the plugin demonstrates good coding practices with 100% of SQL queries utilizing prepared statements and a high percentage of output being properly escaped. The presence of both nonce and capability checks indicates an awareness of common WordPress security vulnerabilities.
However, the static analysis reveals a few areas that warrant attention. While the attack surface appears minimal with no unprotected entry points, the presence of two cron events, although not explicitly detailed in terms of their security, could potentially represent hidden execution paths. The lack of any taint analysis results (0 flows analyzed) could also be a concern; it might indicate that the analysis tools were not configured to effectively trace data flows within this specific plugin, or that there are simply no complex data flows to analyze, which is unlikely for a plugin of this nature. This absence of detailed taint flow information leaves a minor gap in a comprehensive security review.
In conclusion, this plugin appears to be well-secured, with a strong emphasis on safe coding practices and a clean vulnerability history. The main area for consideration is the lack of detailed taint analysis results, which could be a reporting limitation or an indication for further deeper code review if specific concerns arise. Nevertheless, based on the available data, the plugin presents a low-risk profile.
Key Concerns
- No detailed taint analysis data available
- Two cron events present
Kit (formerly ConvertKit) for WPForms Security Vulnerabilities
Kit (formerly ConvertKit) for WPForms Code Analysis
Output Escaping
Kit (formerly ConvertKit) for WPForms Attack Surface
WordPress Hooks 15
Scheduled Events 2
Maintenance & Trust
Kit (formerly ConvertKit) for WPForms Maintenance & Trust
Maintenance Signals
Community Trust
Kit (formerly ConvertKit) for WPForms Alternatives
Kit (formerly ConvertKit) for WooCommerce
convertkit-for-woocommerce
Integrates WooCommerce with Kit allowing customers to be automatically sent to your Kit account.
Gravity Forms ConvertKit Add-On
convertkit-gravity-forms
ConvertKit is an email marketing platform for capturing leads from your WordPress blog.
Easily integrate SendGrid with your WordPress site
contact-manager-for-sendgrid
Contact Manager for SendGrid lets you automatically add new users to a specific SendGrid list. It also integrates with wpforms to add contacts to Sen …
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
Newsletter – Send awesome emails from WordPress
newsletter
An email marketing tool for your blog: subscription forms to create your lists with unlimited subscribers and newsletters.
Kit (formerly ConvertKit) for WPForms Developer Profile
2 plugins · 81K total installs
How We Detect Kit (formerly ConvertKit) for WPForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/integrate-convertkit-wpforms/assets/css/creator-network-recommendations.css/wp-content/plugins/integrate-convertkit-wpforms/assets/js/creator-network-recommendations.js/wp-content/plugins/integrate-convertkit-wpforms/assets/js/convertkit-wpforms.js/wp-content/plugins/integrate-convertkit-wpforms/assets/js/creator-network-recommendations.js/wp-content/plugins/integrate-convertkit-wpforms/assets/js/convertkit-wpforms.jsintegrate-convertkit-wpforms/assets/css/creator-network-recommendations.css?ver=integrate-convertkit-wpforms/assets/js/creator-network-recommendations.js?ver=integrate-convertkit-wpforms/assets/js/convertkit-wpforms.js?ver=HTML / DOM Fingerprints
wpforms-panel-content-section-convertkit<!-- Kit (formerly ConvertKit) for WPForms Plugin. -->data-convertkit-form-iddata-convertkit-connection-iddata-convertkit-creator-network-recommendations-scriptConvertKit_WPForms_Creator_Network_Recommendations