Booster for WPForms Security & Risk Analysis

wordpress.org/plugins/booster-for-wpforms

Extend WPForms by adding some of the most requested functionalties which aren't avaiable in it.

800 active installs v1.2 PHP + WP 4.0+ Updated Apr 3, 2024
wpforms-boosterwpforms-functionalitywpforms-snippets
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Booster for WPForms Safe to Use in 2026?

Generally Safe

Score 92/100

Booster for WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

Based on the static analysis, the "booster-for-wpforms" plugin version 1.2 exhibits a generally good security posture. The absence of any identified CVEs in its vulnerability history, combined with the fact that all SQL queries utilize prepared statements and there are no file operations or dangerous functions, indicates a commitment to secure coding practices. The presence of capability checks further strengthens its defense mechanisms.

However, there are areas for concern. The analysis reveals two flows with unsanitized paths, which, while not resulting in critical or high severity issues according to the taint analysis, represent potential entry points for malicious input. Furthermore, the lack of nonce checks across all identified entry points (entry points are listed as 0, but the lack of nonce checks is a specific code signal) is a significant weakness. While the attack surface appears minimal with zero AJAX handlers, REST API routes, shortcodes, and cron events directly exposed without authentication, any newly introduced functionality could be susceptible if proper nonce validation isn't implemented. The 20% of improperly escaped output also poses a risk of cross-site scripting (XSS) vulnerabilities.

In conclusion, while the plugin has strengths in its SQL handling and vulnerability history, the presence of unsanitized paths, a complete absence of nonce checks, and some unescaped output are critical areas that require immediate attention. Addressing these weaknesses will significantly improve the overall security of the plugin.

Key Concerns

  • Flows with unsanitized paths
  • Lack of nonce checks
  • Unescaped output (20% of 15)
Vulnerabilities
None known

Booster for WPForms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Booster for WPForms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
12 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

80% escaped15 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
show_changelog (admin-menu\EDD_SL_Plugin_Updater.php:399)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Booster for WPForms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
filterpre_set_site_transient_update_pluginsadmin-menu\EDD_SL_Plugin_Updater.php:62
filterplugins_apiadmin-menu\EDD_SL_Plugin_Updater.php:63
actionadmin_initadmin-menu\EDD_SL_Plugin_Updater.php:66
filterpre_set_site_transient_update_pluginsadmin-menu\EDD_SL_Plugin_Updater.php:198
actionadmin_menuadmin-menu\licenses.php:6
actionadmin_initadmin-menu\licenses.php:7
filterwpforms_settings_tabsbooster-for-wpforms.php:35
filterwpforms_settings_defaultsbooster-for-wpforms.php:37
actionwpforms_field_options_bottom_advanced-optionsbooster-for-wpforms.php:39
filterwpforms_field_propertiesbooster-for-wpforms.php:41
filterwpforms_address_schemesbooster-for-wpforms.php:43
filterwpforms_fields_show_options_settingbooster-for-wpforms.php:46
actionwpforms_frontend_output_beforebooster-for-wpforms.php:49
actionwpforms_form_settings_generalbooster-for-wpforms.php:52
filterwpforms_frontend_form_attsbooster-for-wpforms.php:55
actionwpforms_builder_after_panel_contentbooster-for-wpforms.php:58
filterwpforms_builder_settings_sectionsbooster-for-wpforms.php:61
filterwpforms_frontend_stringsbooster-for-wpforms.php:64
actionwpforms_frontend_jsbooster-for-wpforms.php:67
actionwpforms_loadedbooster-for-wpforms.php:763
Maintenance & Trust

Booster for WPForms Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 3, 2024
PHP min version
Downloads8K

Community Trust

Rating20/100
Number of ratings1
Active installs800
Alternatives

Booster for WPForms Alternatives

No alternatives data available yet.

Developer Profile

Booster for WPForms Developer Profile

wpmonks

6 plugins · 71K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Booster for WPForms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/booster-for-wpforms/css/public.css
Version Parameters
booster-for-wpforms/css/public.css?ver=

HTML / DOM Fingerprints

CSS Classes
bfwpf-autocomplete-offbfwpf-entry-count
Data Attributes
data-bfwpf-autocomplete-off
FAQ

Frequently Asked Questions about Booster for WPForms