
WP Subscription Forms – Subscription Form Plugin for WordPress Security & Risk Analysis
wordpress.org/plugins/wp-subscription-formsCreate unlimited subscription forms effortlessly with our user-friendly tool. Collect subscribers directly in WP Backend and export them to CSV.
Is WP Subscription Forms – Subscription Form Plugin for WordPress Safe to Use in 2026?
Generally Safe
Score 96/100WP Subscription Forms – Subscription Form Plugin for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-subscription-forms" v1.2.5 plugin exhibits a concerning security posture despite some positive code practices. While the plugin shows a decent percentage of SQL queries using prepared statements and a reasonable rate of output escaping, the static analysis reveals significant vulnerabilities. A large attack surface, with 10 out of 11 entry points lacking authorization checks, is a major concern. Furthermore, the taint analysis indicates 8 critical flows with unsanitized paths, suggesting potential for severe exploits like Remote Code Execution or SQL Injection. The plugin's vulnerability history, including 3 known CVEs with a past high-severity SQL Injection and PHP Remote File Inclusion, reinforces these concerns. These historical patterns, combined with the current code signals, suggest a recurring weakness in secure coding practices, particularly around input validation and authorization.
Key Concerns
- High number of AJAX handlers without auth checks
- High severity taint flows with unsanitized paths
- Multiple past CVEs with critical/high severity
- Past PHP Remote File Inclusion vulnerability
- Past SQL Injection vulnerability
- Low number of capability checks relative to entry points
- Only 5 nonce checks for 10 unprotected AJAX handlers
WP Subscription Forms – Subscription Form Plugin for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WP Subscription Forms <= 1.2.3 - Missing Authorization
WP Subscription Forms <= 1.2.4 - Authenticated (Contributor+) Local File Inclusion
WP Subscription Forms <= 1.2.3 - Authenticated (Contributor+) SQL Injection
WP Subscription Forms – Subscription Form Plugin for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Subscription Forms – Subscription Form Plugin for WordPress Attack Surface
AJAX Handlers 10
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
WP Subscription Forms – Subscription Form Plugin for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
WP Subscription Forms – Subscription Form Plugin for WordPress Alternatives
Subscription Widget for SendGrid
subscription-widget-for-sendgrid
SG Widget is a Sendgrid Subscription Widget for collecting emails. Just add a shortcode to capture emails and store them in your Sendgrid Account.
Contact Form & SMTP Plugin for WordPress by PirateForms
pirate-forms
A simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
JetWidgets For Elementor
jetwidgets-for-elementor
Addon for Elementor Page builder. It provides the set of widgets to create different kinds of content like pricing tables, posts lists, banners, etc.
MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder
mailchimp-subscribe-sm
MailChimp Subscribe Form allows you to create Beautiful Professional looking Subscribe Forms, Popups, bars & full page optins easily in less than …
Subscriber by BestWebSoft
subscriber
Add email newsletter sign up form to WordPress posts, pages, and widgets. Collect data and subscribe your users.
WP Subscription Forms – Subscription Form Plugin for WordPress Developer Profile
8 plugins · 4K total installs
How We Detect WP Subscription Forms – Subscription Form Plugin for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-subscription-forms/css/wpsf-frontend.css/wp-content/plugins/wp-subscription-forms/css/wpsf-frontend-rtl.css/wp-content/plugins/wp-subscription-forms/fontawesome/css/all.min.css/wp-content/plugins/wp-subscription-forms/js/wpsf-frontend.js/wp-content/plugins/wp-subscription-forms/css/wpsf-preview.css/wp-content/plugins/wp-subscription-forms/css/wpsf-backend.css/wp-content/plugins/wp-subscription-forms/js/wpsf-backend.js/wp-content/plugins/wp-subscription-forms/js/wpsf-frontend.js/wp-content/plugins/wp-subscription-forms/js/wpsf-backend.jswp-subscription-forms/css/wpsf-frontend.css?ver=wp-subscription-forms/fontawesome/css/all.min.css?ver=wp-subscription-forms/js/wpsf-frontend.js?ver=wp-subscription-forms/css/wpsf-preview.css?ver=wp-subscription-forms/css/wpsf-backend.css?ver=wp-subscription-forms/js/wpsf-backend.js?ver=HTML / DOM Fingerprints
wpsf-formwpsf-subscribe-form<!-- Start WPSF Subscription Form --><!-- End WPSF Subscription Form --><!-- WPSF Frontend Form -->data-wpsf-form-idwpsf_frontend_objwpsf_backend_obj[wpsf_form[wpsf_subscribe_form