
ANON::form embedded secure form Security & Risk Analysis
wordpress.org/plugins/anonform-embedded-secure-formEmbed ANON::form's End-to-End Encrypted secure and anonymized web forms into your website with an iframe and a shortcode.
Is ANON::form embedded secure form Safe to Use in 2026?
Generally Safe
Score 99/100ANON::form embedded secure form has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "anonform-embedded-secure-form" plugin v1.8 exhibits a generally good security posture based on static analysis, with no critical or high severity issues found in taint analysis, and a high percentage of properly escaped outputs. The plugin avoids dangerous functions, file operations, and external HTTP requests, which are common sources of vulnerabilities. However, the absence of any nonce checks or capability checks across its entry points, combined with a medium severity Cross-Site Scripting (XSS) vulnerability historically, raises significant concerns. While no unpatched CVEs are currently listed, the past XSS issue indicates a potential weakness in input sanitization, and the lack of robust authorization checks on its single shortcode entry point means that any user could potentially trigger its functionality, which might be exploited if combined with an unpatched or newly discovered vulnerability. The plugin's strengths lie in its avoidance of complex functionalities that often introduce bugs, but its vulnerability history and lack of authorization checks represent the most significant risks.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- History of Medium severity XSS
- High percentage of unescaped outputs (19%)
ANON::form embedded secure form Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
ANON::form embedded secure form <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
ANON::form embedded secure form Release Timeline
ANON::form embedded secure form Code Analysis
Output Escaping
ANON::form embedded secure form Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
ANON::form embedded secure form Maintenance & Trust
Maintenance Signals
Community Trust
ANON::form embedded secure form Alternatives
SiteGuard WP Plugin
siteguard
Adds WordPress login and admin protections, including CAPTCHA, login lock, login alerts, renamed login URLs, and SiteGuard WAF tuning support.
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
contact-form-7-honeypot
Add hCaptcha, Honeypot, and Redirection to Contact Form 7 with CF7 Apps, and generate forms effortlessly with AI. Improve form security, keep it light …
Really Simple CAPTCHA
really-simple-captcha
Really Simple CAPTCHA is a CAPTCHA module intended to be called from other plugins. It is originally created for my Contact Form 7 plugin.
Advanced Google reCAPTCHA
advanced-google-recaptcha
Captcha protection against spam comments & brute force login attacks using Google reCAPTCHA.
CleanTalk Anti-Spam. Spam Firewall & Bot protection
cleantalk-spam-protect
Top-rated antispam for contact forms, comments, WooCommerce, eCommerce, and login. No CAPTCHAs, no friction, just background anti spam protection.
ANON::form embedded secure form Developer Profile
1 plugin · 10 total installs
How We Detect ANON::form embedded secure form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/anonform-embedded-secure-form/css/embed-anonform.cssanonform-embedded-secure-form/css/embed-anonform.css?ver=HTML / DOM Fingerprints
anon-admin-noticeanon-admin-notice-contentanon-admin-notice-messageanon-col-12anon-admin-notice-headeranon-flexanon-buttonanon-button-review+4 moreid="anonform-div"id="anonform-app"loading="lazy"title="Embedded secure form from ANON::form"data-noncewindow.anonform<div id="anonform-div"><iframe id="anonform-app" src="