
AForms — Form Builder for Price Calculator & Cost Estimation Security & Risk Analysis
wordpress.org/plugins/aforms-form-builder-for-price-calculator-cost-estimationForm builder for Cost estimation and Custom order.
Is AForms — Form Builder for Price Calculator & Cost Estimation Safe to Use in 2026?
Generally Safe
Score 91/100AForms — Form Builder for Price Calculator & Cost Estimation has a strong security track record. Known vulnerabilities have been patched promptly.
The aforms-form-builder-for-price-calculator-cost-estimation plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and having no known unpatched vulnerabilities. The absence of critical or high-severity taint analysis findings and dangerous functions is also encouraging.
However, significant concerns arise from the large attack surface composed of 13 entry points, with 10 of these being AJAX handlers lacking authentication checks. This is a critical weakness, as it exposes these handlers to potential abuse by unauthenticated users. While the plugin has a history of one medium-severity "Exposure of Sensitive Information to an Unauthorized Actor" vulnerability, the current lack of unpatched issues is a positive sign. The 61% proper output escaping rate also indicates room for improvement, as a portion of outputs might be vulnerable to cross-site scripting (XSS) if data is not properly sanitized.
In conclusion, the plugin has strengths in its database query security and a clean recent vulnerability history. Nevertheless, the unprotected AJAX handlers represent a substantial security risk that attackers could exploit. Addressing these unprotected entry points should be a top priority to improve the plugin's overall security.
Key Concerns
- Unprotected AJAX handlers
- Moderate output escaping rate
- Medium severity historical vulnerability
AForms — Form Builder for Price Calculator & Cost Estimation Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
AForms <= 2.2.6 - Unauthenticated Full Path Disclosure
AForms — Form Builder for Price Calculator & Cost Estimation Code Analysis
SQL Query Safety
Output Escaping
AForms — Form Builder for Price Calculator & Cost Estimation Attack Surface
AJAX Handlers 10
Shortcodes 3
WordPress Hooks 10
Maintenance & Trust
AForms — Form Builder for Price Calculator & Cost Estimation Maintenance & Trust
Maintenance Signals
Community Trust
AForms — Form Builder for Price Calculator & Cost Estimation Alternatives
ConvertCalculator: Build Cost, Price, Quotation, ROI Interactive Calculators
convertcalculator
Easily build calculators for your landing pages and web applications with Convert_'s intuitive calculator builder.
Cost Calculator Builder
cost-calculator-builder
WP Cost Calculator is a simple and powerful tool that lets you create price estimation forms. Easily give your clients information about your services …
Cost Calculator & Cost Estimation
cost-calculator-cost-estimation
Cost Calculator & Cost Estimation helps you to build any type of estimation forms on a few easy steps.
MultiStep Checkout for WooCommerce
woo-multistep-checkout
MultiStep Checkout for WooCommerce Split up your WooCommerce Checkout form easily into simpler steps.
Flexible Quantity – Measurement Price Calculator for WooCommerce
flexible-quantity-measurement-price-calculator-for-woocommerce
WooCommerce price calculator. Sell products by unit, dimension or volume. Calculate quantity increment and final price for a new unit of measure.
AForms — Form Builder for Price Calculator & Cost Estimation Developer Profile
2 plugins · 3K total installs
How We Detect AForms — Form Builder for Price Calculator & Cost Estimation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aforms-form-builder-for-price-calculator-cost-estimation/asset/front.js/wp-content/plugins/aforms-form-builder-for-price-calculator-cost-estimation/asset/front.cssaforms-form-builder-for-price-calculator-cost-estimation/asset/front.js?ver=HTML / DOM Fingerprints
aforms-form-wrapperdata-aforms-form-idaformsAForms/wp-json/aforms/v1/custom/wp-json/aforms/v1/order-new[aforms-form][aforms-result][aforms-orderid]