ANON::form embedded secure form Security & Risk Analysis

wordpress.org/plugins/anonform-embedded-secure-form

Embed ANON::form's End-to-End Encrypted secure and anonymized web forms into your website with an iframe and a shortcode.

10 active installs v1.8 PHP 5.6+ WP 5.0+ Updated Nov 28, 2025
captchaend-to-end-encryptiongdpr-compliancesecure-formwhistleblower-form
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 19, 2025
Safety Verdict

Is ANON::form embedded secure form Safe to Use in 2026?

Generally Safe

Score 99/100

ANON::form embedded secure form has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 19, 2025Updated 4mo ago
Risk Assessment

The "anonform-embedded-secure-form" plugin v1.8 exhibits a generally good security posture based on static analysis, with no critical or high severity issues found in taint analysis, and a high percentage of properly escaped outputs. The plugin avoids dangerous functions, file operations, and external HTTP requests, which are common sources of vulnerabilities. However, the absence of any nonce checks or capability checks across its entry points, combined with a medium severity Cross-Site Scripting (XSS) vulnerability historically, raises significant concerns. While no unpatched CVEs are currently listed, the past XSS issue indicates a potential weakness in input sanitization, and the lack of robust authorization checks on its single shortcode entry point means that any user could potentially trigger its functionality, which might be exploited if combined with an unpatched or newly discovered vulnerability. The plugin's strengths lie in its avoidance of complex functionalities that often introduce bugs, but its vulnerability history and lack of authorization checks represent the most significant risks.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • History of Medium severity XSS
  • High percentage of unescaped outputs (19%)
Vulnerabilities
1

ANON::form embedded secure form Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-52733medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

ANON::form embedded secure form <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jun 19, 2025 Patched in 1.8 (7d)
Code Analysis
Analyzed Mar 16, 2026

ANON::form embedded secure form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

81% escaped27 total outputs
Attack Surface

ANON::form embedded secure form Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[anonform] embed-anonform.php:39
WordPress Hooks 7
actionadmin_initembed-anonform-review.php:9
actionadmin_initembed-anonform-review.php:10
actionadmin_enqueue_scriptsembed-anonform-review.php:11
actionadmin_noticesembed-anonform-review.php:12
actionadmin_noticesembed-anonform-review.php:41
actionadmin_print_footer_scriptsembed-anonform-review.php:42
actionwp_enqueue_scriptsembed-anonform.php:40
Maintenance & Trust

ANON::form embedded secure form Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version5.6
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

ANON::form embedded secure form Developer Profile

Anonform Ab

1 plugin · 10 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect ANON::form embedded secure form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/anonform-embedded-secure-form/css/embed-anonform.css
Version Parameters
anonform-embedded-secure-form/css/embed-anonform.css?ver=

HTML / DOM Fingerprints

CSS Classes
anon-admin-noticeanon-admin-notice-contentanon-admin-notice-messageanon-col-12anon-admin-notice-headeranon-flexanon-buttonanon-button-review+4 more
Data Attributes
id="anonform-div"id="anonform-app"loading="lazy"title="Embedded secure form from ANON::form"data-nonce
JS Globals
window.anonform
Shortcode Output
<div id="anonform-div"><iframe id="anonform-app" src="
FAQ

Frequently Asked Questions about ANON::form embedded secure form