Ninja Forms – MailPoet Security & Risk Analysis

wordpress.org/plugins/ninja-forms-mailpoet

This extension integrates Ninja Forms with MailPoet by providing an option to add users who submit a form to an existing newsletter.

200 active installs v1.0.0 PHP + WP 3.7+ Updated May 19, 2015
formformsmailpoetninja-formswysija
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Ninja Forms – MailPoet Safe to Use in 2026?

Generally Safe

Score 85/100

Ninja Forms – MailPoet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the ninja-forms-mailpoet v1.0.0 plugin exhibits an exceptionally secure posture. The complete absence of known vulnerabilities, dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and taint flows with unsanitized paths is a strong indicator of robust development practices. The attack surface is also entirely protected, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that lack proper authentication or permission checks.

While the lack of identified vulnerabilities and a clean static analysis report are highly positive, the complete absence of certain security checks like nonces and capability checks across all potential entry points (even though there are none in this version) could be a concern in future, more complex versions of the plugin. However, for this specific version, the analysis indicates no immediate exploitable risks. The plugin's track record of zero CVEs further reinforces its current security. Overall, this version appears very secure, with strengths far outweighing any minor potential concerns for future development.

Vulnerabilities
None known

Ninja Forms – MailPoet Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Ninja Forms – MailPoet Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Ninja Forms – MailPoet Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initmailpoet-ninja-forms.php:81
actionninja_forms_post_processmailpoet-ninja-forms.php:168
actioninitmailpoet-ninja-forms.php:170
Maintenance & Trust

Ninja Forms – MailPoet Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedMay 19, 2015
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

Ninja Forms – MailPoet Developer Profile

Jean

6 plugins · 340 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ninja Forms – MailPoet

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Ninja Forms – MailPoet