
MailPoet Add-On for FormCraft Security & Risk Analysis
wordpress.org/plugins/mailpoet-for-formcraftCreate gorgeous optin forms for your site with FormCraft, and grow your MailPoet list.
Is MailPoet Add-On for FormCraft Safe to Use in 2026?
Generally Safe
Score 85/100MailPoet Add-On for FormCraft has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "mailpoet-for-formcraft" v1.0.1 reveals a plugin with a seemingly minimal attack surface and no direct indications of dangerous functions or SQL injection vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events suggests a limited interaction with the WordPress core, which is generally a positive sign. The reported use of prepared statements for SQL queries further bolsters this perception of good practice in database interaction.
However, a significant concern arises from the complete lack of output escaping. This means that any data outputted by the plugin, regardless of its origin, is not being sanitized for potentially malicious content. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is ever displayed directly to other users without proper sanitization. The lack of any recorded vulnerabilities in its history is a strength, suggesting a stable codebase. Yet, without more detailed historical data, it's difficult to draw strong conclusions about its long-term security track record.
In conclusion, while the plugin demonstrates strengths in avoiding common pitfalls like unauthenticated entry points and raw SQL, the critical oversight in output escaping presents a notable risk. The absence of vulnerabilities in its history is encouraging, but the static analysis highlights a specific, actionable security concern that requires attention to ensure a more robust security posture.
Key Concerns
- No output escaping
MailPoet Add-On for FormCraft Security Vulnerabilities
MailPoet Add-On for FormCraft Code Analysis
Output Escaping
MailPoet Add-On for FormCraft Attack Surface
WordPress Hooks 3
Maintenance & Trust
MailPoet Add-On for FormCraft Maintenance & Trust
Maintenance Signals
Community Trust
MailPoet Add-On for FormCraft Alternatives
Lead Form Builder & Contact Form
lead-form-builder
Fast Drag & Drop Contact From Builder and Lead Generation Tool With Google One Tap Login. Supports Block Editor.
FormCraft – Form Builder
formcraft-form-builder
Create gorgeous forms for your site using this drag-and-drop form builder.
MailChimp Add-On for FormCraft
mailchimp-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your MailChimp list.
Mailster Add-On for FormCraft
formcraft-mymail
Create gorgeous optin forms for your site with FormCraft, and grow your Mailster list.
GetResponse Add-On for FormCraft
getresponse-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your GetResponse list.
MailPoet Add-On for FormCraft Developer Profile
8 plugins · 11K total installs
How We Detect MailPoet Add-On for FormCraft
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mailpoet-for-formcraft/assets/builder.js/wp-content/plugins/mailpoet-for-formcraft/assets/builder.cssassets/builder.jsformcraft-mailpoet-main-jsformcraft-mailpoet-main-cssHTML / DOM Fingerprints
mailpoet-coverfc-spinnermailpoet-mapnos-{{Addons.MailPoet.Map.length}}ng-repeat='instance in Addons.MailPoet.Map'ng-model='instance.formField'ng-click='removeMap($index)'ng-model='SelectedList'ng-model='SelectedColumn'ng-model='FieldName'+1 moreAddons.MailPoet.MapWYSIJA<div id='mailpoet-cover'><div id='mapped-mailpoet'<div id='mailpoet-map'><select class='select-list'