
AForms Eats Security & Risk Analysis
wordpress.org/plugins/aforms-eatsAn order form builder for restaurants. You can create comfortable order forms and sell your food online.
Is AForms Eats Safe to Use in 2026?
Generally Safe
Score 91/100AForms Eats has a strong security track record. Known vulnerabilities have been patched promptly.
The aforms-eats plugin v1.3.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices in several areas, notably the complete absence of raw SQL queries, with all 22 queries utilizing prepared statements. Additionally, the plugin includes one nonce check and three capability checks, which are important security mechanisms. However, a significant concern arises from the extensive attack surface that lacks authentication. Out of 12 total entry points, a concerning 11 are AJAX handlers that do not have any authentication checks, leaving them potentially vulnerable to unauthorized access and execution. While the taint analysis found no critical or high severity flows, indicating no immediately obvious path for arbitrary code execution or data leakage through unsanitized inputs in the analyzed flows, the lack of authorization on most AJAX handlers remains a primary risk.
The plugin's vulnerability history shows one known medium-severity CVE related to the generation of error messages containing sensitive information. Although this vulnerability is currently patched, the pattern of past vulnerabilities, even if medium, suggests that the plugin might have had issues with robust error handling or input validation. The fact that there are no currently unpatched CVEs is a positive indicator. In conclusion, while the plugin shows strengths in SQL handling and some security checks, the overwhelming majority of its AJAX handlers are unprotected, creating a substantial risk. This, combined with a history of even medium-severity vulnerabilities, indicates that users should exercise caution and ensure their WordPress installation is up-to-date to mitigate potential risks from the past or any undiscovered vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- Past medium severity vulnerability
- Limited capability checks
AForms Eats Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
AForms Eats <= 1.3.1 - Unauthenticated Full Path Disclosure
AForms Eats Code Analysis
SQL Query Safety
Output Escaping
AForms Eats Attack Surface
AJAX Handlers 11
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
AForms Eats Maintenance & Trust
Maintenance Signals
Community Trust
AForms Eats Alternatives
Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin
orderable
Take your restaurant/food business online with the online ordering system plugin for WordPress, Orderable.
Food Menu – Restaurant Menu & Online Ordering for WooCommerce
tlp-food-menu
A Simple Food & Restaurant Menu Display Plugin for Restaurant, Cafes, Fast Food, Coffee House with WooCommerce Online Ordering.
Food Store – Online Food Delivery & Pickup
food-store
Food Store is complete online food ordering platform with all your favourite WooCommerce functionalities.
RestroPress – Online Food Ordering System
restropress
RestroPress is a Food Ordering System for WordPress which will help the restaurant owners to sell their food online.
FoodBook Lite – Online Food Ordering System
foodbook-light-online-food-ordering-system
Short Description: WooCommerce-based food ordering and restaurant delivery management plugin.
AForms Eats Developer Profile
2 plugins · 3K total installs
How We Detect AForms Eats
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aforms-eats/asset/front.js/wp-content/plugins/aforms-eats/asset/front.jsaforms-eats/asset/front.js?ver=HTML / DOM Fingerprints
/wp-json/aforms-eats/v1/form/wp-json/aforms-eats/v1/settings/wp-json/aforms-eats/v1/order/wp-json/aforms-eats/v1/confirm/wp-json/aforms-eats/v1/order-new[aforms-eats-form]