
Mailster Gravity Forms Security & Risk Analysis
wordpress.org/plugins/mailster-gravity-formsIntegrates Mailster Newsletter Plugin with Gravity Forms to subscribe users with a Gravity Form.
Is Mailster Gravity Forms Safe to Use in 2026?
Generally Safe
Score 92/100Mailster Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mailster-gravity-forms" v2.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, external HTTP requests, or file operations. The complete absence of SQL queries that are not prepared statements is a significant strength, as is the fact that all observed SQL queries use prepared statements. The presence of nonce and capability checks, while only one of each is noted, suggests an awareness of WordPress security best practices. The plugin also reports zero known vulnerabilities, historical or current, which is a positive indicator.
However, a significant concern arises from the very low percentage (11%) of properly escaped output. With 18 total outputs analyzed, 15 of them are potentially unescaped, creating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. While the attack surface appears minimal with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are not protected, the lack of proper output sanitization leaves a critical gap. The taint analysis showing zero flows with unsanitized paths is encouraging, but it might not be comprehensive if the output escaping is so low.
Given the lack of known vulnerabilities and the absence of critical taint flows, the plugin has some robust security measures in place. Nevertheless, the high number of unescaped outputs represents a serious and exploitable risk that overshadows the other positive findings. This weakness needs to be addressed promptly to prevent potential XSS attacks that could compromise user data or site integrity.
Key Concerns
- Low percentage of properly escaped output (11%)
Mailster Gravity Forms Security Vulnerabilities
Mailster Gravity Forms Code Analysis
Output Escaping
Mailster Gravity Forms Attack Surface
WordPress Hooks 4
Maintenance & Trust
Mailster Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Mailster Gravity Forms Alternatives
Mailster WordPress Newsletter Plugin
mailster
Send beautiful newsletters from WordPress. Collect subscribers with signup forms, automate your emails for WooCommerce, blog post notifications & …
Drip for WordPress
email-marketing
Do you sell online? If so you need our new Drip for WooCommerce Plugin instead of this one. It includes your entire product catalog, order history int …
Newsletters
newsletters-lite
Newsletter plugin for WordPress to capture subscribers and send beautiful, bulk newsletter emails.
Benchmark Email Lite
benchmark-email-lite
Your Wordpress Site and Email Marketing all in one place!
Get a Newsletter
getanewsletter
Turn visitors into subscribers. Eliminate manual entry of subscribers with signup forms that sync directly with your Get a Newsletter account.
Mailster Gravity Forms Developer Profile
28 plugins · 121K total installs
How We Detect Mailster Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mailster-gravity-forms/assets/style.cssmailster-gravity-forms/assets/style.css?ver=HTML / DOM Fingerprints
gform-icon--mailsterdata-inputmask<h3>Please enable the <a href="https://mailster.co/?utm_campaign=wporg&utm_source=wordpress.org&utm_medium=plugin&utm_term=Gravity+Forms">Mailster Newsletter Plugin</a></h3>