
MailChimp Add-On for FormCraft Security & Risk Analysis
wordpress.org/plugins/mailchimp-for-formcraftCreate gorgeous optin forms for your site with FormCraft, and grow your MailChimp list.
Is MailChimp Add-On for FormCraft Safe to Use in 2026?
Generally Safe
Score 85/100MailChimp Add-On for FormCraft has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mailchimp-for-formcraft plugin v1.8 exhibits several significant security concerns, primarily stemming from its unprotected entry points. While the plugin demonstrates good practices in terms of SQL query handling and appears to have no known historical vulnerabilities, the presence of three AJAX handlers without authentication checks creates a substantial attack surface. This lack of authorization means that any user, even unauthenticated ones, could potentially trigger these handlers, leading to unintended actions or information disclosure.
Furthermore, the analysis indicates that 100% of the plugin's output is not properly escaped. This is a critical flaw that opens the door to cross-site scripting (XSS) vulnerabilities. Attackers could inject malicious scripts through user-controllable data that is later displayed by the plugin, potentially compromising user sessions or defacing the website. The absence of nonce checks on these AJAX handlers exacerbates this risk, as it removes another layer of defense against CSRF attacks. Despite the clean vulnerability history and secure SQL usage, these fundamental security oversights in input validation and output escaping present a high risk.
Key Concerns
- AJAX handlers without authentication checks
- Output escaping is not implemented
- Missing nonce checks on AJAX handlers
MailChimp Add-On for FormCraft Security Vulnerabilities
MailChimp Add-On for FormCraft Code Analysis
Output Escaping
MailChimp Add-On for FormCraft Attack Surface
AJAX Handlers 3
WordPress Hooks 3
Maintenance & Trust
MailChimp Add-On for FormCraft Maintenance & Trust
Maintenance Signals
Community Trust
MailChimp Add-On for FormCraft Alternatives
reCaptcha Add-On for FormCraft
formcraft-recaptcha
Add reCaptcha to your FormCraft forms.
Subscribe Forms – Beautiful Email Forms, Embedded Newsletter Forms & MailChimp Form
wp-subscribe-form
Use Subscribe Forms to grow your email subscriber lists with Subscribe Forms built-in email forms templates and integrations 📧
GetResponse Add-On for FormCraft
getresponse-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your GetResponse list.
Campaign Monitor Add-On for FormCraft
campaign-monitor-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your Campaign Monitor list.
MailPoet Add-On for FormCraft
mailpoet-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your MailPoet list.
MailChimp Add-On for FormCraft Developer Profile
8 plugins · 11K total installs
How We Detect MailChimp Add-On for FormCraft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mailchimp-for-formcraft/assets/builder.js/wp-content/plugins/mailchimp-for-formcraft/assets/builder.cssassets/builder.jsmailchimp-for-formcraft/assets/builder.js?ver=mailchimp-for-formcraft/assets/builder.css?ver=HTML / DOM Fingerprints
mc-paddingtrigger-helpmc-valid-api-keynos-mc-map-outputformcraft-loader<!-- Add a Field Mapping Below -->data-post-id='19'Addons.MailChimpformcraft_mailchimp_test_apiformcraft_mailchimp_get_listsformcraft_mailchimp_get_columns/wp-json/formcraft-mailchimp/v1/test_api/wp-json/formcraft-mailchimp/v1/get_lists/wp-json/formcraft-mailchimp/v1/get_columns