
MailerLite – Signup forms (official) Security & Risk Analysis
wordpress.org/plugins/official-mailerlite-sign-up-formsAdd newsletter signup forms to your WordPress site. Subscribers will be saved directly to your MailerLite account. Super easy to set up!
Is MailerLite – Signup forms (official) Safe to Use in 2026?
Generally Safe
Score 86/100MailerLite – Signup forms (official) has a strong security track record. Known vulnerabilities have been patched promptly.
The "official-mailerlite-sign-up-forms" plugin exhibits a mixed security posture. While it demonstrates good practices in SQL query handling and includes a reasonable number of nonce and capability checks, significant concerns remain. The presence of unprotected AJAX handlers presents a direct attack surface that could be exploited by unauthenticated users. Furthermore, the taint analysis revealed two high-severity flows with unsanitized paths, indicating potential vulnerabilities that could lead to data compromise or unauthorized actions. The plugin's vulnerability history is a major red flag, with a substantial number of past CVEs, including critical and high-severity issues. The common vulnerability types like Missing Authorization, CSRF, XSS, and SQL Injection, coupled with a recent critical vulnerability, suggest a pattern of recurring security weaknesses that have not been fully addressed.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Critical past CVE
- High past CVE
- Medium past CVEs (5)
- Low output escaping
- Dangerous function (unserialize)
- Bundled library (TinyMCE)
MailerLite – Signup forms (official) Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
MailerLite – Signup forms (official) <= 1.7.16 - Authenticated (Administrator+) Stored Cross-Site Scripting
MailerLite – Signup forms (official) 1.5.0 - 1.7.6 - Authenticated (Contributor+) Stored Cross-Site Scripting
MailerLite – Signup forms (official) <= 1.7.6 - Missing Authorization
MailerLite – Signup forms (official) <= 1.5.7 - Cross-Site Request Forgery
MailerLite - Signup forms <= 1.5.3 - Reflected Cross-Site Scripting
MailerLite Signup Forms < 1.4.4 - Unauthenticated SQL Injection
MailerLite – Signup forms <= 1.4.4 - Cross-Site Request Forgery
MailerLite – Signup forms (official) Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
MailerLite – Signup forms (official) Attack Surface
AJAX Handlers 10
Shortcodes 1
WordPress Hooks 27
Maintenance & Trust
MailerLite – Signup forms (official) Maintenance & Trust
Maintenance Signals
Community Trust
MailerLite – Signup forms (official) Alternatives
Enormail Sign Up Forms
enormail-sign-up-forms
Add an Enormail signup form to your Wordpress website and start growing your list.
EmailSystem
emailsystem
Use a Drag and Drop Form Builder to create Subscription Forms for the EmailSystem email marketing platform.
MC4WP: Mailchimp for WordPress
mailchimp-for-wp
The #1 Mailchimp plugin for WordPress. Allows you to add a multitude of newsletter sign-up methods to your site.
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
MailMunch – Grow your Email List
mailmunch
The best free plugin to get more email subscribers. Beautiful opt-in forms that integrate with MailChimp, Constant Contact, AWeber, Campaign Monitor a …
MailerLite – Signup forms (official) Developer Profile
3 plugins · 132K total installs
How We Detect MailerLite – Signup forms (official)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/official-mailerlite-sign-up-forms/assets/css/mailerlite.css/wp-content/plugins/official-mailerlite-sign-up-forms/assets/css/mailerlite_forms.css/wp-content/plugins/official-mailerlite-sign-up-forms/assets/js/mailerlite_block.js/wp-content/plugins/official-mailerlite-sign-up-forms/assets/js/mailerlite_block.jsofficial-mailerlite-sign-up-forms/assets/css/mailerlite.css?ver=official-mailerlite-sign-up-forms/assets/css/mailerlite_forms.css?ver=official-mailerlite-sign-up-forms/assets/js/mailerlite_block.js?ver=HTML / DOM Fingerprints
mailerlite-form-blockmailerlite_form_block/wp-json/mailerlite/v1/gutenberg-forms/wp-json/mailerlite/v1/gutenberg-form-preview/wp-json/mailerlite/v1/gutenberg-form-preview2