Authyo OTP for Everest Forms Security & Risk Analysis

wordpress.org/plugins/authyo-otp-for-everest-forms

Adds email and phone number OTP verification to Everest Forms with support for SMS, WhatsApp, and Voice.

0 active installs v1.0.0 PHP 7.4+ WP 5.5+ Updated Mar 25, 2026
email-otpeverest-formseverest-forms-otpeverest-forms-phone-verificationphone-otp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Authyo OTP for Everest Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Authyo OTP for Everest Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The Authyo OTP for Everest Forms plugin, version 1.0.0, exhibits a strong security posture based on the provided static analysis. A notable strength is the complete absence of dangerous functions, file operations, and critical/high severity taint flows. All SQL queries are properly prepared, and output escaping is 100% effective, indicating robust data handling practices. The plugin also demonstrates good security awareness with nonce checks and capability checks in place. The vulnerability history showing zero known CVEs further reinforces this positive assessment, suggesting a well-maintained and secure codebase.

While the plugin has a minimal attack surface with no unprotected entry points, there are a few minor areas that could be further strengthened. The presence of external HTTP requests, although not inherently a vulnerability, warrants careful monitoring to ensure they are made securely and to trusted endpoints. The plugin also utilizes external dependencies which, if not kept updated, could introduce risks. Overall, the plugin appears to be developed with security in mind, and the current version presents a low-risk profile. Future updates should continue to prioritize secure coding practices and prompt patching of any newly discovered vulnerabilities.

Key Concerns

  • External HTTP requests present
  • Nonce checks are present, but could be more extensive if attack surface grows
Vulnerabilities
None known

Authyo OTP for Everest Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Authyo OTP for Everest Forms Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Authyo OTP for Everest Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
0
213 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

100% escaped213 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
render_settings (includes/class-authyo-everest-forms-admin.php:142)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Authyo OTP for Everest Forms Attack Surface

Entry Points2
Unprotected0

REST API Routes 2

POST/wp-json/authyo-everest-forms/v1/sendincludes/class-authyo-everest-forms-frontend.php:24
POST/wp-json/authyo-everest-forms/v1/verifyincludes/class-authyo-everest-forms-frontend.php:30
WordPress Hooks 14
actionplugins_loadedauthyo-otp-for-everest-forms.php:43
actionadmin_noticesauthyo-otp-for-everest-forms.php:45
filtereverest_forms_fieldsauthyo-otp-for-everest-forms.php:58
actionwp_enqueue_scriptsauthyo-otp-for-everest-forms.php:87
actionadmin_enqueue_scriptsauthyo-otp-for-everest-forms.php:130
filterpre_update_option_authyo_everest_forms_settingsauthyo-otp-for-everest-forms.php:148
actionadmin_menuincludes/class-authyo-everest-forms-admin.php:16
actionadmin_initincludes/class-authyo-everest-forms-admin.php:17
actionadmin_enqueue_scriptsincludes/class-authyo-everest-forms-admin.php:18
filterwp_redirectincludes/class-authyo-everest-forms-admin.php:19
filteradmin_body_classincludes/class-authyo-everest-forms-admin.php:21
actionadmin_initincludes/class-authyo-everest-forms-admin.php:24
actionrest_api_initincludes/class-authyo-everest-forms-frontend.php:16
filtereverest_forms_process_initial_errorsincludes/class-authyo-everest-forms-frontend.php:17
Maintenance & Trust

Authyo OTP for Everest Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 25, 2026
PHP min version7.4
Downloads107

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Authyo OTP for Everest Forms Developer Profile

Konceptwise Digital Media Pvt Ltd

11 plugins · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Authyo OTP for Everest Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/authyo-otp-for-everest-forms/assets/css/frontend.css/wp-content/plugins/authyo-otp-for-everest-forms/assets/js/frontend.js/wp-content/plugins/authyo-otp-for-everest-forms/assets/js/smart-field.js/wp-content/plugins/authyo-otp-for-everest-forms/assets/css/admin.css/wp-content/plugins/authyo-otp-for-everest-forms/assets/js/admin.js
Version Parameters
authyo-otp-for-everest-forms/assets/css/frontend.css?ver=authyo-otp-for-everest-forms/assets/js/frontend.js?ver=authyo-otp-for-everest-forms/assets/js/smart-field.js?ver=authyo-otp-for-everest-forms/assets/css/admin.css?ver=authyo-otp-for-everest-forms/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
authyo-otp-evf-wrapperauthyo-otp-evf-field-email-inputauthyo-otp-evf-field-phone-inputauthyo-otp-evf-smart-inputauthyo-otp-verify-buttonauthyo-otp-resend-buttonauthyo-otp-status-message
Data Attributes
data-authyo-otp-field-typedata-authyo-otp-field-id
JS Globals
AUTHYO_EVEREST_FORMSAUTHYO_EVEREST_FORMS_ADMIN
REST Endpoints
/wp-json/authyo-everest-forms/v1/send-otp/wp-json/authyo-everest-forms/v1/verify-otp/wp-json/authyo-everest-forms/v1/admin/settings
FAQ

Frequently Asked Questions about Authyo OTP for Everest Forms