MailPoet Add-On for FormCraft Security & Risk Analysis

wordpress.org/plugins/mailpoet-for-formcraft

Create gorgeous optin forms for your site with FormCraft, and grow your MailPoet list.

70 active installs v1.0.1 PHP + WP 3.6+ Updated Jun 6, 2015
contact-form-7contact-form-builderform-buildermailpoetnewsletter-form
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MailPoet Add-On for FormCraft Safe to Use in 2026?

Generally Safe

Score 85/100

MailPoet Add-On for FormCraft has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The static analysis of "mailpoet-for-formcraft" v1.0.1 reveals a plugin with a seemingly minimal attack surface and no direct indications of dangerous functions or SQL injection vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events suggests a limited interaction with the WordPress core, which is generally a positive sign. The reported use of prepared statements for SQL queries further bolsters this perception of good practice in database interaction.

However, a significant concern arises from the complete lack of output escaping. This means that any data outputted by the plugin, regardless of its origin, is not being sanitized for potentially malicious content. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is ever displayed directly to other users without proper sanitization. The lack of any recorded vulnerabilities in its history is a strength, suggesting a stable codebase. Yet, without more detailed historical data, it's difficult to draw strong conclusions about its long-term security track record.

In conclusion, while the plugin demonstrates strengths in avoiding common pitfalls like unauthenticated entry points and raw SQL, the critical oversight in output escaping presents a notable risk. The absence of vulnerabilities in its history is encouraging, but the static analysis highlights a specific, actionable security concern that requires attention to ensure a more robust security posture.

Key Concerns

  • No output escaping
Vulnerabilities
None known

MailPoet Add-On for FormCraft Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MailPoet Add-On for FormCraft Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

MailPoet Add-On for FormCraft Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionformcraft_after_saveformcraft-mailpoet.php:19
actionformcraft_addon_initformcraft-mailpoet.php:66
actionformcraft_addon_scriptsformcraft-mailpoet.php:67
Maintenance & Trust

MailPoet Add-On for FormCraft Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedJun 6, 2015
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

MailPoet Add-On for FormCraft Developer Profile

Formcrafts

8 plugins · 11K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
823 days
View full developer profile
Detection Fingerprints

How We Detect MailPoet Add-On for FormCraft

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mailpoet-for-formcraft/assets/builder.js/wp-content/plugins/mailpoet-for-formcraft/assets/builder.css
Script Paths
assets/builder.js
Version Parameters
formcraft-mailpoet-main-jsformcraft-mailpoet-main-css

HTML / DOM Fingerprints

CSS Classes
mailpoet-coverfc-spinnermailpoet-mapnos-{{Addons.MailPoet.Map.length}}
Data Attributes
ng-repeat='instance in Addons.MailPoet.Map'ng-model='instance.formField'ng-click='removeMap($index)'ng-model='SelectedList'ng-model='SelectedColumn'ng-model='FieldName'+1 more
JS Globals
Addons.MailPoet.MapWYSIJA
Shortcode Output
<div id='mailpoet-cover'><div id='mapped-mailpoet'<div id='mailpoet-map'><select class='select-list'
FAQ

Frequently Asked Questions about MailPoet Add-On for FormCraft