Mailster Gravity Forms Security & Risk Analysis

wordpress.org/plugins/mailster-gravity-forms

Integrates Mailster Newsletter Plugin with Gravity Forms to subscribe users with a Gravity Form.

900 active installs v2.0.0 PHP + WP 6.0+ Updated May 27, 2024
email-marketingmailing-listmailsternewsletternewsletters
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mailster Gravity Forms Safe to Use in 2026?

Generally Safe

Score 92/100

Mailster Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "mailster-gravity-forms" v2.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, external HTTP requests, or file operations. The complete absence of SQL queries that are not prepared statements is a significant strength, as is the fact that all observed SQL queries use prepared statements. The presence of nonce and capability checks, while only one of each is noted, suggests an awareness of WordPress security best practices. The plugin also reports zero known vulnerabilities, historical or current, which is a positive indicator.

However, a significant concern arises from the very low percentage (11%) of properly escaped output. With 18 total outputs analyzed, 15 of them are potentially unescaped, creating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. While the attack surface appears minimal with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are not protected, the lack of proper output sanitization leaves a critical gap. The taint analysis showing zero flows with unsanitized paths is encouraging, but it might not be comprehensive if the output escaping is so low.

Given the lack of known vulnerabilities and the absence of critical taint flows, the plugin has some robust security measures in place. Nevertheless, the high number of unescaped outputs represents a serious and exploitable risk that overshadows the other positive findings. This weakness needs to be addressed promptly to prevent potential XSS attacks that could compromise user data or site integrity.

Key Concerns

  • Low percentage of properly escaped output (11%)
Vulnerabilities
None known

Mailster Gravity Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mailster Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
2 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

11% escaped18 total outputs
Attack Surface

Mailster Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedclasses\gravity.class.php:18
filtergform_after_submissionclasses\gravity.class.php:28
filtergform_form_settings_menuclasses\gravity.class.php:32
actiongform_form_settings_page_mailsterclasses\gravity.class.php:33
Maintenance & Trust

Mailster Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 27, 2024
PHP min version
Downloads18K

Community Trust

Rating86/100
Number of ratings4
Active installs900
Developer Profile

Mailster Gravity Forms Developer Profile

EverPress

28 plugins · 121K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
255 days
View full developer profile
Detection Fingerprints

How We Detect Mailster Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mailster-gravity-forms/assets/style.css
Version Parameters
mailster-gravity-forms/assets/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
gform-icon--mailster
Data Attributes
data-inputmask
Shortcode Output
<h3>Please enable the <a href="https://mailster.co/?utm_campaign=wporg&utm_source=wordpress.org&utm_medium=plugin&utm_term=Gravity+Forms">Mailster Newsletter Plugin</a></h3>
FAQ

Frequently Asked Questions about Mailster Gravity Forms