Chatterbug Forms – Fast, Flexible WordPress Form Builder Security & Risk Analysis

wordpress.org/plugins/chatterbug-forms

Free unlimited forms and submissions. Create your forms on wp.ChatterbugForms.com for free with easy drag and drop then import them into your site.

10 active installs v1.0.2 PHP 7.4+ WP 5.8+ Updated Oct 3, 2025
contact-formform-builderformsfree-formssurveys
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Chatterbug Forms – Fast, Flexible WordPress Form Builder Safe to Use in 2026?

Generally Safe

Score 100/100

Chatterbug Forms – Fast, Flexible WordPress Form Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "chatterbug-forms" v1.0.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates strong coding practices in several areas. Notably, 100% of output is properly escaped, and 93% of SQL queries utilize prepared statements, significantly reducing the risk of common web vulnerabilities like XSS and SQL injection. The plugin also incorporates a substantial number of nonce checks, indicating an effort to protect against CSRF attacks.

However, the static analysis reveals critical areas of concern. The presence of one AJAX handler without any authentication checks creates a significant attack vector. Furthermore, the taint analysis highlights four high-severity flows with unsanitized paths, which could potentially lead to privilege escalation, data leakage, or other serious security issues if not properly handled. The complete absence of capability checks is also a notable weakness, as it means these entry points are not secured against unauthorized user actions.

The plugin's vulnerability history is remarkably clean, with no known CVEs. This is a positive indicator, suggesting a generally secure development process or that existing vulnerabilities have been addressed. However, the presence of high-severity taint flows in the current version contradicts this history and suggests that potential risks might exist that haven't been publicly documented or exploited yet. While the lack of historical vulnerabilities is encouraging, the current code analysis points to specific, actionable risks that need immediate attention.

Key Concerns

  • Unprotected AJAX handler
  • High severity unsanitized taint flows
  • No capability checks
Vulnerabilities
None known

Chatterbug Forms – Fast, Flexible WordPress Form Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Chatterbug Forms – Fast, Flexible WordPress Form Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
68 prepared
Unescaped Output
0
392 escaped
Nonce Checks
20
Capability Checks
0
File Operations
3
External Requests
4
Bundled Libraries
0

SQL Query Safety

93% prepared73 total queries

Output Escaping

100% escaped392 total outputs
Data Flows
6 unsanitized

Data Flow Analysis

10 flows6 with unsanitized paths
<dashboard> (dashboard\dashboard.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Chatterbug Forms – Fast, Flexible WordPress Form Builder Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 2

authwp_ajax_cbforms_importformlistchatterbug-forms.php:759
noprivwp_ajax_cbforms_importformlistchatterbug-forms.php:760

Shortcodes 1

[chatterbugforms] chatterbug-forms.php:253
WordPress Hooks 9
actionadmin_enqueue_scriptschatterbug-forms.php:38
actionadmin_enqueue_scriptschatterbug-forms.php:61
actionadmin_menuchatterbug-forms.php:180
actionpre_get_postschatterbug-forms.php:325
actionafter_setup_themedashboard\dashboard.php:5
actionwp_mail_failedinc\cbforms-global-settings.php:18
actionplugins_loadedinc\cbforms-install.php:13
actionphpmailer_initinc\cbforms_mailer.php:16
filterwp_mail_frominc\cbforms_mailer.php:28
Maintenance & Trust

Chatterbug Forms – Fast, Flexible WordPress Form Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 3, 2025
PHP min version7.4
Downloads505

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Chatterbug Forms – Fast, Flexible WordPress Form Builder Developer Profile

Sam Gazal

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Chatterbug Forms – Fast, Flexible WordPress Form Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/chatterbug-forms/assets/css/cbforms-admin-style.css/wp-content/plugins/chatterbug-forms/assets/css/cbfp_forms.css/wp-content/plugins/chatterbug-forms/assets/js/cbforms-admin.js/wp-content/plugins/chatterbug-forms/assets/js/cbfformview.js
Script Paths
https://www.google.com/recaptcha/api.jshttps://fonts.googleapis.com/css2?family=Material+Symbols+Outlined:opsz,wght,FILL,GRAD@24,400,0,0https://fonts.googleapis.com/css2?family=Material+Symbols+Outlined:opsz,wght,FILL,GRAD@20..48,100..700,0..1,-50..200

HTML / DOM Fingerprints

CSS Classes
cbforms-form-submit-msgcbforms-confirmation-msgcbforms-form-request-msgcbforms-unavailable-msg
Data Attributes
cbforms_nonce
Shortcode Output
[chatterbugformscbforms_getform
FAQ

Frequently Asked Questions about Chatterbug Forms – Fast, Flexible WordPress Form Builder