MailPoet Gravity Forms Add-on Security & Risk Analysis

wordpress.org/plugins/mailpoet-gravity-forms-add-on

Adds a new field for you to allow your visitors to subscriber to your MailPoet newsletters.

100 active installs v2.0.4 PHP + WP 3.7.1+ Updated Aug 19, 2014
extensiongravity-formsmailpoetsebs-studiowysija
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is MailPoet Gravity Forms Add-on Safe to Use in 2026?

Generally Safe

Score 85/100

MailPoet Gravity Forms Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The MailPoet Gravity Forms Add-on v2.0.4 demonstrates a generally strong security posture with no recorded vulnerabilities and a clean vulnerability history. The static analysis reveals a minimal attack surface with zero AJAX handlers, REST API routes, shortcodes, or cron events. Crucially, all SQL queries are prepared, indicating a good practice against SQL injection. Nonce and capability checks are present, further strengthening the security against common WordPress exploits. The absence of dangerous functions and file operations is also a positive sign.

However, there are areas for improvement. The most significant concern is the low percentage of properly escaped output (19%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed. While no critical or high severity taint flows were found, this low output escaping rate still presents a risk. The presence of an external HTTP request, while not inherently malicious, is a point to monitor as it could become a vector if not handled securely. The plugin's zero CVE history is commendable and suggests a proactive approach to security by the developers. Overall, while the plugin has a solid foundation, the output escaping needs significant attention to mitigate potential XSS risks.

Key Concerns

  • Low percentage of properly escaped output
  • Presence of external HTTP requests
Vulnerabilities
None known

MailPoet Gravity Forms Add-on Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MailPoet Gravity Forms Add-on Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
4 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

19% escaped21 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
settings_page (includes\admin\views\view-html-settings.php:13)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

MailPoet Gravity Forms Add-on Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actioncurrent_screenincludes\admin\class-mailpoet-gravity-forms-admin-help.php:24
actioninitincludes\admin\class-mailpoet-gravity-forms-admin.php:22
actioncurrent_screenincludes\admin\class-mailpoet-gravity-forms-admin.php:23
actionadmin_initincludes\admin\class-mailpoet-gravity-forms-install.php:26
filtergform_logging_supportedincludes\admin\mailpoet-gravity-forms-admin-hooks.php:14
filtergform_add_field_buttonsincludes\admin\mailpoet-gravity-forms-admin-hooks.php:21
filtergform_field_type_titleincludes\admin\mailpoet-gravity-forms-admin-hooks.php:22
filtergform_tooltipsincludes\admin\mailpoet-gravity-forms-admin-hooks.php:23
actiongform_editor_jsincludes\admin\mailpoet-gravity-forms-admin-hooks.php:26
actiongform_field_standard_settingsincludes\admin\mailpoet-gravity-forms-admin-hooks.php:27
actiongform_field_css_classincludes\admin\mailpoet-gravity-forms-admin-hooks.php:28
actiongform_field_inputincludes\mailpoet-gravity-forms-core-functions.php:23
actiongform_after_submissionincludes\mailpoet-gravity-forms-hooks.php:13
actioninitmailpoet-gravity-forms-addon.php:168
actionadmin_noticesmailpoet-gravity-forms-addon.php:249
actionadmin_noticesmailpoet-gravity-forms-addon.php:255
actionadmin_noticesmailpoet-gravity-forms-addon.php:261
actionadmin_noticesmailpoet-gravity-forms-addon.php:269
actionadmin_noticesmailpoet-gravity-forms-addon.php:270
actionadmin_noticesmailpoet-gravity-forms-addon.php:275
Maintenance & Trust

MailPoet Gravity Forms Add-on Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedAug 19, 2014
PHP min version
Downloads12K

Community Trust

Rating80/100
Number of ratings4
Active installs100
Developer Profile

MailPoet Gravity Forms Add-on Developer Profile

Sébastien Dumont

15 plugins · 2K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MailPoet Gravity Forms Add-on

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mailpoet-gravity-forms-add-on/assets/css/mailpoet-gravity-forms-addon.css/wp-content/plugins/mailpoet-gravity-forms-add-on/assets/js/mailpoet-gravity-forms-addon.js
Script Paths
/wp-content/plugins/mailpoet-gravity-forms-add-on/assets/js/mailpoet-gravity-forms-addon.js
Version Parameters
/wp-content/plugins/mailpoet-gravity-forms-add-on/assets/css/mailpoet-gravity-forms-addon.css?ver=/wp-content/plugins/mailpoet-gravity-forms-add-on/assets/js/mailpoet-gravity-forms-addon.js?ver=

HTML / DOM Fingerprints

CSS Classes
mailpoet-gravity-forms-add-on-settings
HTML Comments
Copyright: (c) 2014 Sebs Studio. (sebastien@sebs-studio.com)License: GNU General Public License v3.0License URI: http://www.gnu.org/licenses/gpl-3.0.html@package MailPoet_Gravity_Forms_Add_on+3 more
Data Attributes
data-plugin-name="MailPoet Gravity Forms Add-on"data-plugin-version="2.0.4"
JS Globals
MAILPOET_GFMAILPOET_GF_SLUGMAILPOET_GF_FILEMAILPOET_GF_VERSIONMAILPOET_GF_WP_VERSION_REQUIREMAILPOET_GF_VERSION_REQUIRE+6 more
FAQ

Frequently Asked Questions about MailPoet Gravity Forms Add-on