
Automation for WPForms Security & Risk Analysis
wordpress.org/plugins/automation-for-wpformsCreate automatic actions using WPForms
Is Automation for WPForms Safe to Use in 2026?
Generally Safe
Score 85/100Automation for WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "automation-for-wpforms" plugin v1.24 exhibits a mixed security posture. On the positive side, it has no recorded vulnerability history, indicating a generally stable development process. The plugin also demonstrates good practices with a high percentage of SQL queries using prepared statements and a decent rate of output escaping.
However, there are notable concerns arising from the static analysis. The presence of two AJAX handlers without authentication checks represents a significant attack surface. Furthermore, the taint analysis reveals four flows with unsanitized paths, even though they are not classified as critical or high severity. This suggests potential for unintended behavior or data manipulation if user-supplied input is not handled rigorously, especially in conjunction with the unprotected AJAX endpoints.
While the lack of known CVEs is reassuring, the presence of unprotected entry points and unsanitized flows warrants caution. The plugin's strengths lie in its SQL preparation and output escaping, but the immediate risk stems from the unprotected AJAX handlers which could be exploited if they process user input in any way. A balanced conclusion is that the plugin is not inherently insecure, but requires immediate attention to secure its AJAX endpoints and to ensure all data flow paths are adequately sanitized.
Key Concerns
- AJAX handlers without auth checks
- Flows with unsanitized paths
- No capability checks
Automation for WPForms Security Vulnerabilities
Automation for WPForms Release Timeline
Automation for WPForms Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Automation for WPForms Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
Automation for WPForms Maintenance & Trust
Maintenance Signals
Community Trust
Automation for WPForms Alternatives
Views for WPForms – Display & Edit WPForms Entries on your site frontend
views-for-wpforms-lite
Display and Edit WPForms Entries Directly on Your Website with No Coding Knowledge Needed.
Page Builder for WPForms – Display your WPForms entries in any page
page-builder-for-wpforms
In a few clicks create listings, calendars, tables, confirmation pages or everything you need using your WPForms entries. No coding required.
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
WPSyncSheets For WPForms – Google Sheets Connector for WPForms & Real‑Time Data Export
wpsyncsheets-wpforms
Connect WPForms to Google Sheets and automatically sync form entries in real-time. Eliminate manual data entry and simplify your workflow.
Views for Elementor Forms – Display & Edit Submissions on your site frontend
views-for-elementor-forms
Display and edit your Elementor Forms entries directly on the frontend of your website.
Automation for WPForms Developer Profile
19 plugins · 12K total installs
How We Detect Automation for WPForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.