
Any Form Security & Risk Analysis
wordpress.org/plugins/anyformVery simple and customisable contact form with database integration and control panel.
Is Any Form Safe to Use in 2026?
Generally Safe
Score 85/100Any Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "anyform" v1.0.1 plugin exhibits a generally positive security posture due to its adherence to several good development practices. Notably, all SQL queries are performed using prepared statements, and there are no external HTTP requests or file operations, significantly reducing common attack vectors. The presence of a nonce check, while only one, is a positive sign. However, there are significant concerns regarding output escaping, with only 32% of outputs being properly escaped. This indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the user interface. Furthermore, the taint analysis reveals three flows with unsanitized paths, although these did not reach a critical or high severity in the static analysis, they still represent potential weaknesses that could be exploited if combined with other factors or in different contexts. The lack of any recorded vulnerability history is a positive indicator of past stability but should not be relied upon solely, as new vulnerabilities can emerge in any software. Overall, while the plugin avoids some critical pitfalls, the poor output escaping and the presence of unsanitized paths are significant weaknesses that require immediate attention.
Key Concerns
- Low output escaping percentage
- Unsanitized paths in taint analysis flows
Any Form Security Vulnerabilities
Any Form Release Timeline
Any Form Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Any Form Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Any Form Maintenance & Trust
Maintenance Signals
Community Trust
Any Form Alternatives
Ninja Forms – The Contact Form Builder That Grows With You
ninja-forms
The 100% beginner friendly WordPress form builder. Drag & drop form fields to build beautiful, professional contact forms in minutes.
CF7 Woo Product Registration
cf7-woo-product-registration
Add a form field to Contact Form 7 forms to include your products from WooCommerce to create a product registration form or return authorization (RMA) …
Affiliate Contact Form 7 Integration For WooCommerce
affiliate-contact-form-7-integration-for-woocommerce
Recruit better affiliates for your affiliate program by gathering detailed insights through Contact Form 7 (CF7) powered custom registration forms.
Normalized Forms with Captcha
normalized-forms-with-captcha
Custom Responsive Contact, Login & Register Forms with Captcha. Redirection of Register and Login links to a theme based Register page.
neoForms
neoforms
Now you can build form in easiest, simplest and fastest ever way however you want without coding.
Any Form Developer Profile
1 plugin · 0 total installs
How We Detect Any Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/anyform/css/style.cssHTML / DOM Fingerprints
anyform-containername="phone4"name="submitted"<div id="anyform-container"><form method="post" onsubmit="submit.disabled = true; return true;">