Add entries functionality to WPForms Security & Risk Analysis

wordpress.org/plugins/add-entries-functionality-to-wpforms

This plugin adds the functionality of saving WPforms entries into database, displaying them on WP dashboard, exporting WPForms entries in csv and also …

100 active installs v1.3.5 PHP 7.0.33+ WP 1.0.0+ Updated May 8, 2022
entriesentryexportwpformwprforms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Add entries functionality to WPForms Safe to Use in 2026?

Generally Safe

Score 85/100

Add entries functionality to WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

This plugin exhibits a generally strong security posture with excellent practices in place. The absence of any known CVEs and a clean vulnerability history across all severity levels is highly positive. Furthermore, the static analysis reveals a commendable use of prepared statements for all SQL queries and a very high percentage of properly escaped output, minimizing risks of SQL injection and cross-site scripting (XSS) respectively. The limited attack surface with no unprotected entry points is also a significant strength.

However, a few areas warrant attention. The complete absence of capability checks is a notable concern, as it suggests that privileged actions might be accessible to users without the necessary permissions. While the static analysis didn't reveal any critical taint flows, the lack of such analysis (0 flows analyzed) means potential vulnerabilities in this area cannot be ruled out. The presence of file operations, while not inherently risky, could become a point of exploitation if not handled with extreme care, especially in conjunction with the lack of capability checks.

In conclusion, the plugin has a solid foundation with good security practices evident. The lack of historical vulnerabilities is reassuring. The primary weaknesses lie in the absence of capability checks and the incomplete taint analysis, which, while not immediately indicative of a problem, represent potential blind spots. Addressing these areas would further solidify the plugin's security.

Key Concerns

  • No capability checks for entry points
  • Taint analysis not performed
Vulnerabilities
None known

Add entries functionality to WPForms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Add entries functionality to WPForms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
21 prepared
Unescaped Output
2
21 escaped
Nonce Checks
1
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared21 total queries

Output Escaping

91% escaped23 total outputs
Attack Surface

Add entries functionality to WPForms Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ank-wpform-entries] includes\frontend\entries-shortcode.php:64
WordPress Hooks 16
actionwpforms_admin_menuadd-wpform-entries.php:167
actionwpforms_process_entry_saveadd-wpform-entries.php:170
filterwpforms_overview_row_actionsadd-wpform-entries.php:173
actionin_plugin_update_message-add-wpform-entries/add-wpform-entries.phpadd-wpform-entries.php:290
actionadmin_initincludes\admin\entry\entries-page.php:29
actionadmin_initincludes\admin\entry\entries-page.php:32
actionload-wpforms_page_ank-wpforms-entriesincludes\admin\entry\entries-page.php:35
actionload-wpforms_page_ank-wpforms-entriesincludes\admin\entry\entries-page.php:37
actionload-wpforms_page_ank-wpforms-entriesincludes\admin\entry\entries-page.php:38
filterset-screen-optionincludes\admin\entry\entries-page.php:39
filterset_screen_option_ank_entries_per_pageincludes\admin\entry\entries-page.php:40
actionadmin_enqueue_scriptsincludes\admin\entry\entries-page.php:65
actionentry_admin_pageincludes\admin\entry\entries-page.php:66
actionadmin_noticesincludes\admin\entry\entries-page.php:92
actionplugins_loadedincludes\ank-entry-install.php:18
actionadmin_noticesincludes\ank-entry-install.php:20
Maintenance & Trust

Add entries functionality to WPForms Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMay 8, 2022
PHP min version7.0.33
Downloads4K

Community Trust

Rating100/100
Number of ratings4
Active installs100
Developer Profile

Add entries functionality to WPForms Developer Profile

ankgne

2 plugins · 110 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add entries functionality to WPForms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-entries-functionality-to-wpforms/includes/frontend/entries-shortcode.php

HTML / DOM Fingerprints

JS Globals
Ank_WPForms_Shortcode
FAQ

Frequently Asked Questions about Add entries functionality to WPForms