
Ajaxy Forms Security & Risk Analysis
wordpress.org/plugins/ajaxy-formsAjaxy Forms empowers developers to craft powerful and dynamic WordPress forms with complete code-first control.
Is Ajaxy Forms Safe to Use in 2026?
Generally Safe
Score 92/100Ajaxy Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ajaxy-forms" plugin v1.0.4 demonstrates a generally strong security posture based on the provided static analysis. It effectively utilizes prepared statements for all SQL queries and a high percentage of its output is properly escaped, which are crucial security practices. The absence of known CVEs and a clean vulnerability history further indicate a well-maintained and secure plugin. However, the analysis does reveal some potential areas for improvement and careful consideration.
The presence of 4 flows with unsanitized paths in the taint analysis, despite being classified as non-critical, warrants attention. These flows could potentially be exploited if an attacker can control the data flowing through them. The single file operation and multiple external HTTP requests, while not inherently insecure, represent potential attack vectors if not handled with extreme care and proper input validation. The limited attack surface with only one AJAX handler, which is noted as having an authentication check, is a positive aspect.
Overall, "ajaxy-forms" v1.0.4 appears to be a relatively secure plugin, prioritizing fundamental security measures. The lack of historical vulnerabilities is a significant strength. However, the identified unsanitized path flows in the taint analysis and the presence of file operations and external HTTP requests suggest that further scrutiny and potentially enhanced validation for these specific code paths would be beneficial to further strengthen its security.
Key Concerns
- Flows with unsanitized paths in taint analysis
- Presence of file operations
- External HTTP requests present
Ajaxy Forms Security Vulnerabilities
Ajaxy Forms Release Timeline
Ajaxy Forms Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Ajaxy Forms Attack Surface
AJAX Handlers 1
WordPress Hooks 13
Maintenance & Trust
Ajaxy Forms Maintenance & Trust
Maintenance Signals
Community Trust
Ajaxy Forms Alternatives
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder
everest-forms
The best WordPress form builder. Create contact forms, payment forms, conversational forms, custom forms, surveys, & quizzes using drag and drop.
Drag and Drop Multiple File Upload for Contact Form 7
drag-and-drop-multiple-file-upload-contact-form-7
This simple plugin create Drag & Drop or choose Multiple File upload in your Confact Form 7 Forms.
Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
form-maker
Form Maker is a user-friendly contact form builder that allows to create forms for any purpose, from a simple contact form to multi page survey forms
NEX-Forms – Ultimate Forms Plugin for WordPress
nex-forms-express-wp-form-builder
Build beautiful responsive forms for WordPress. Contact forms, surveys, quizzes, booking forms, payments, popups & more with NEX-Forms...
FormCraft – Form Builder
formcraft-form-builder
Create gorgeous forms for your site using this drag-and-drop form builder.
Ajaxy Forms Developer Profile
2 plugins · 10 total installs
How We Detect Ajaxy Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ajaxy-forms/build/js/script.js/wp-content/plugins/ajaxy-forms/build/css/style.css/wp-content/plugins/ajaxy-forms/build/js/script.jsajaxy-forms/build/css/style.css?ver=ajaxy-forms/build/js/script.js?ver=HTML / DOM Fingerprints
ajaxy-formajaxy-forms-wrapperdata-ajaxy-form-nameajaxy_forms_form_validation_rulesajaxy_forms_form_validation_messages/wp-json/ajaxy-forms/v1/form/[form name=""][form name="some_form_name"]