
Airy Frontend Forms Security & Risk Analysis
wordpress.org/plugins/airy-frontend-formsCreate powerful frontend submission forms for ACF and SCF with complete control over fields, taxonomies, and user submissions.
Is Airy Frontend Forms Safe to Use in 2026?
Generally Safe
Score 100/100Airy Frontend Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "airy-frontend-forms" v1.0.0 plugin presents a mixed security posture. On the positive side, it demonstrates good practices by extensively utilizing prepared statements for SQL queries and performing robust output escaping, with 84% and 90% respectively. The plugin also includes a healthy number of nonce and capability checks, indicating an awareness of common WordPress security mechanisms. Furthermore, its vulnerability history is clean, with zero recorded CVEs, suggesting a stable and likely well-maintained codebase in terms of known past issues.
However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers without any authentication checks, creating a direct entry point for unauthenticated users. This is exacerbated by the taint analysis, which reveals 16 high-severity flows with unsanitized paths. These flows, combined with the unprotected AJAX handlers, pose a substantial risk of arbitrary code execution or data manipulation if an attacker can leverage these unsanitized inputs. The presence of file operations and external HTTP requests, while not explicitly flagged as risky in this analysis, also warrants cautious monitoring given the unsanitized path issues.
In conclusion, while the plugin has a clean vulnerability history and good internal coding practices regarding SQL and output sanitization, the critical taint analysis results coupled with unprotected AJAX endpoints represent a significant and immediate security risk. Addressing these high-severity unsanitized path flows and securing the AJAX handlers should be the highest priority.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows with unsanitized paths
Airy Frontend Forms Security Vulnerabilities
Airy Frontend Forms Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Airy Frontend Forms Attack Surface
AJAX Handlers 17
Shortcodes 3
WordPress Hooks 20
Maintenance & Trust
Airy Frontend Forms Maintenance & Trust
Maintenance Signals
Community Trust
Airy Frontend Forms Alternatives
No alternatives data available yet.
Airy Frontend Forms Developer Profile
2 plugins · 20 total installs
How We Detect Airy Frontend Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/airy-frontend-forms/assets/css/admin-style.css/wp-content/plugins/airy-frontend-forms/assets/css/frontend-style.css/wp-content/plugins/airy-frontend-forms/assets/js/admin-script.js/wp-content/plugins/airy-frontend-forms/assets/js/frontend-script.js/wp-content/plugins/airy-frontend-forms/assets/js/form-builder.js/wp-content/plugins/airy-frontend-forms/assets/js/admin-script.js/wp-content/plugins/airy-frontend-forms/assets/js/frontend-script.js/wp-content/plugins/airy-frontend-forms/assets/js/form-builder.jsairy-frontend-forms/assets/css/admin-style.css?ver=airy-frontend-forms/assets/css/frontend-style.css?ver=airy-frontend-forms/assets/js/admin-script.js?ver=airy-frontend-forms/assets/js/frontend-script.js?ver=airy-frontend-forms/assets/js/form-builder.js?ver=HTML / DOM Fingerprints
affcf-form-wrapperaffcf-frontend-formaffcf-form-field<!-- Main Admin Class<!-- Exit if accessed directly.<!-- Initialize admin components.<!-- AJAX handlers for field groups.+14 moredata-affcf-form-iddata-affcf-field-idAFFCF_Admin_Form_BuilderAFFCF_Frontend_Form/wp-json/affcf/v1/forms/wp-json/affcf/v1/forms/(?P<id>\d+)/wp-json/affcf/v1/field-groups/wp-json/affcf/v1/field-groups/(?P<id>\d+)/wp-json/affcf/v1/taxonomies[airy-frontend-form id="[affcf_frontend_form id="