
Authyo OTP for Forminator Form Security & Risk Analysis
wordpress.org/plugins/authyo-otp-for-forminator-formSecure your Forminator forms with Authyo OTP Verification (Email, SMS, WhatsApp, Voice).
Is Authyo OTP for Forminator Form Safe to Use in 2026?
Generally Safe
Score 100/100Authyo OTP for Forminator Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The authyo-otp-for-forminator-form plugin v1.0.3 demonstrates a strong security posture based on the provided static analysis. All identified entry points (AJAX handlers and REST API routes) appear to have appropriate authentication and permission checks, which is a significant strength. The code also shows excellent practice regarding SQL queries, with 100% using prepared statements, and a high level of output escaping (92%). The absence of dangerous functions, file operations, and any recorded vulnerabilities in its history further bolsters this positive assessment.
While the overall picture is good, there are a couple of minor points to consider. The plugin makes 6 external HTTP requests, and while not explicitly stated as a risk in the analysis, the nature of these requests and how they are handled warrants attention to prevent potential vulnerabilities like SSRF if not implemented securely. Similarly, with 9 AJAX handlers and 5 capability checks, it's important to ensure that the logic within these handlers is robust and that the capability checks are consistently applied to prevent privilege escalation or unauthorized actions, although the analysis did not uncover specific issues here.
In conclusion, the plugin exhibits good security practices, particularly in its handling of entry points and data sanitization. The lack of known vulnerabilities is a very positive indicator. The primary areas for vigilance would be the secure implementation of external HTTP requests and a continued focus on maintaining robust authorization checks within its handlers. The absence of critical findings in the taint analysis is reassuring.
Key Concerns
- External HTTP requests present
Authyo OTP for Forminator Form Security Vulnerabilities
Authyo OTP for Forminator Form Code Analysis
Output Escaping
Data Flow Analysis
Authyo OTP for Forminator Form Attack Surface
AJAX Handlers 7
REST API Routes 2
WordPress Hooks 13
Maintenance & Trust
Authyo OTP for Forminator Form Maintenance & Trust
Maintenance Signals
Community Trust
Authyo OTP for Forminator Form Alternatives
Authyo OTP for WPForms
authyo-otp-for-wpforms
Adds email and phone number OTP verification to WPForms with support for SMS, WhatsApp, and Voice.
User Verification by PickPlugins
user-verification
Email verification for user registration to protect spam.
GSheetConnector for Forminator Forms
gsheetconnector-forminator
Send your Forminator Forms data directly to your Google Sheet in a real-time.
Email OTP Authenticator – for Login, Registration or 2FA, RWL, RWA Services
email-otp-authenticator
Use an OTP to Login, Register, 2FA OR allow interim premium access WITHOUT Login, even WITHOUT Account. It is FAST, FRIENDLY, SMART, SMOOTH & SECURED.
Electronic Signature Add-on for Forminator
forms-digital-signature-forminator-add-on
Instantly produce a legally binding PDF WordPress contract from a Forminator Forms contact form submission. Digital Signature Pad. Proposal.
Authyo OTP for Forminator Form Developer Profile
10 plugins · 10 total installs
How We Detect Authyo OTP for Forminator Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.