
Authyo OTP for Forminator Form Security & Risk Analysis
wordpress.org/plugins/authyo-otp-for-forminator-formStop spam and verify real users — add Email, SMS, WhatsApp, or Voice OTP verification to any Forminator form in minutes.
Is Authyo OTP for Forminator Form Safe to Use in 2026?
Generally Safe
Score 100/100Authyo OTP for Forminator Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The authyo-otp-for-forminator-form plugin v1.0.3 demonstrates a strong security posture based on the provided static analysis. All identified entry points (AJAX handlers and REST API routes) appear to have appropriate authentication and permission checks, which is a significant strength. The code also shows excellent practice regarding SQL queries, with 100% using prepared statements, and a high level of output escaping (92%). The absence of dangerous functions, file operations, and any recorded vulnerabilities in its history further bolsters this positive assessment.
While the overall picture is good, there are a couple of minor points to consider. The plugin makes 6 external HTTP requests, and while not explicitly stated as a risk in the analysis, the nature of these requests and how they are handled warrants attention to prevent potential vulnerabilities like SSRF if not implemented securely. Similarly, with 9 AJAX handlers and 5 capability checks, it's important to ensure that the logic within these handlers is robust and that the capability checks are consistently applied to prevent privilege escalation or unauthorized actions, although the analysis did not uncover specific issues here.
In conclusion, the plugin exhibits good security practices, particularly in its handling of entry points and data sanitization. The lack of known vulnerabilities is a very positive indicator. The primary areas for vigilance would be the secure implementation of external HTTP requests and a continued focus on maintaining robust authorization checks within its handlers. The absence of critical findings in the taint analysis is reassuring.
Key Concerns
- External HTTP requests present
Authyo OTP for Forminator Form Security Vulnerabilities
Authyo OTP for Forminator Form Release Timeline
Authyo OTP for Forminator Form Code Analysis
Output Escaping
Data Flow Analysis
Authyo OTP for Forminator Form Attack Surface
AJAX Handlers 7
REST API Routes 2
WordPress Hooks 13
Maintenance & Trust
Authyo OTP for Forminator Form Maintenance & Trust
Maintenance Signals
Community Trust
Authyo OTP for Forminator Form Alternatives
Authyo OTP for Contact Form 7
authyo-otp-for-contact-form-7
Add OTP verification (Email & Phone) to Contact Form 7. Reduce spam and allow only verified users via SMS, WhatsApp, Email, or Voice Call.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
WP Armour – Honeypot Anti Spam
honeypot
Fastest growing Anti Spam plugin. No API calls, subscriptions, captcha or puzzle. Full GDPR complaint. For comments, contact form, login, registration
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
contact-form-7-honeypot
Add hCaptcha, Honeypot, and Redirection to Contact Form 7 with CF7 Apps, and generate forms effortlessly with AI. Improve form security, keep it light …
Authyo OTP for Forminator Form Developer Profile
16 plugins · 40 total installs
How We Detect Authyo OTP for Forminator Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.