
MailPoet Gravity Forms Add-on Security & Risk Analysis
wordpress.org/plugins/mailpoet-gravity-forms-add-onAdds a new field for you to allow your visitors to subscriber to your MailPoet newsletters.
Is MailPoet Gravity Forms Add-on Safe to Use in 2026?
Generally Safe
Score 85/100MailPoet Gravity Forms Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The MailPoet Gravity Forms Add-on v2.0.4 demonstrates a generally strong security posture with no recorded vulnerabilities and a clean vulnerability history. The static analysis reveals a minimal attack surface with zero AJAX handlers, REST API routes, shortcodes, or cron events. Crucially, all SQL queries are prepared, indicating a good practice against SQL injection. Nonce and capability checks are present, further strengthening the security against common WordPress exploits. The absence of dangerous functions and file operations is also a positive sign.
However, there are areas for improvement. The most significant concern is the low percentage of properly escaped output (19%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not consistently sanitized before being displayed. While no critical or high severity taint flows were found, this low output escaping rate still presents a risk. The presence of an external HTTP request, while not inherently malicious, is a point to monitor as it could become a vector if not handled securely. The plugin's zero CVE history is commendable and suggests a proactive approach to security by the developers. Overall, while the plugin has a solid foundation, the output escaping needs significant attention to mitigate potential XSS risks.
Key Concerns
- Low percentage of properly escaped output
- Presence of external HTTP requests
MailPoet Gravity Forms Add-on Security Vulnerabilities
MailPoet Gravity Forms Add-on Code Analysis
Output Escaping
Data Flow Analysis
MailPoet Gravity Forms Add-on Attack Surface
WordPress Hooks 20
Maintenance & Trust
MailPoet Gravity Forms Add-on Maintenance & Trust
Maintenance Signals
Community Trust
MailPoet Gravity Forms Add-on Alternatives
MailPoet bbPress Add-on
mailpoet-bbpress-add-on
Enables your new forum members to subscribe to a newsletter while registering on the forum. Requires the use of [bbp-register] shortcode.
MailPoet WP e-Commerce Add-on
mailpoet-wp-e-commerce-add-on
Adds a checkbox on checkout page for your customers to subscribe to your MailPoet newsletters.
Gravity Pre-submission Confirmation
gravity-pre-submission-confirmation
A WordPress plugin which adds a pre-submission confirmation page to your Graviy forms where users can preview their entered data before they submit it …
Add-on Gravity Forms – MailPoet 3
add-on-gravity-forms-mailpoet
Create MailPoet 3 newsletter subscribers from Gravity Form entries.
Add-on WooCommerce – MailPoet 3
add-on-woocommerce-mailpoet
Let your customers subscribe to your MailPoet 3 newsletter as they checkout from WooCommerce with their purchase.
MailPoet Gravity Forms Add-on Developer Profile
15 plugins · 2K total installs
How We Detect MailPoet Gravity Forms Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mailpoet-gravity-forms-add-on/assets/css/mailpoet-gravity-forms-addon.css/wp-content/plugins/mailpoet-gravity-forms-add-on/assets/js/mailpoet-gravity-forms-addon.js/wp-content/plugins/mailpoet-gravity-forms-add-on/assets/js/mailpoet-gravity-forms-addon.js/wp-content/plugins/mailpoet-gravity-forms-add-on/assets/css/mailpoet-gravity-forms-addon.css?ver=/wp-content/plugins/mailpoet-gravity-forms-add-on/assets/js/mailpoet-gravity-forms-addon.js?ver=HTML / DOM Fingerprints
mailpoet-gravity-forms-add-on-settingsCopyright: (c) 2014 Sebs Studio. (sebastien@sebs-studio.com)License: GNU General Public License v3.0License URI: http://www.gnu.org/licenses/gpl-3.0.html@package MailPoet_Gravity_Forms_Add_on+3 moredata-plugin-name="MailPoet Gravity Forms Add-on"data-plugin-version="2.0.4"MAILPOET_GFMAILPOET_GF_SLUGMAILPOET_GF_FILEMAILPOET_GF_VERSIONMAILPOET_GF_WP_VERSION_REQUIREMAILPOET_GF_VERSION_REQUIRE+6 more