
Corymbus Forms Security & Risk Analysis
wordpress.org/plugins/corymbus-formsCorymbus Forms provides the [corymbus-forms] shortcode which lets you easily embed in your website a web form/page published from the Corymbus CRM.
Is Corymbus Forms Safe to Use in 2026?
Generally Safe
Score 85/100Corymbus Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'corymbus-forms' plugin version 1.1.3 demonstrates a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, and output escaping issues is commendable. Furthermore, the lack of known CVEs and a clean vulnerability history suggests good development practices and a history of secure releases. The attack surface appears limited, with only one shortcode entry point and no unprotected AJAX handlers or REST API routes. The total lack of taint flows, including those with unsanitized paths, further reinforces the impression of a secure codebase.
However, the analysis does highlight a significant concern: the absence of nonce checks and capability checks. While the current attack surface is small and appears to have no direct unprotected entry points, the lack of these fundamental security mechanisms leaves the plugin vulnerable to potential Cross-Site Request Forgery (CSRF) attacks if the single shortcode were to be exploited or if future functionality were to introduce new attack vectors. This oversight, while not immediately exploitable given the current limited scope, represents a weakness that could be exploited in a broader context or with future plugin updates. Therefore, while the plugin is currently secure, this specific omission warrants attention for future hardening.
Key Concerns
- Missing nonce checks
- Missing capability checks
Corymbus Forms Security Vulnerabilities
Corymbus Forms Code Analysis
Output Escaping
Corymbus Forms Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Corymbus Forms Maintenance & Trust
Maintenance Signals
Community Trust
Corymbus Forms Alternatives
AFI – The Easiest Integration Plugin
advanced-form-integration
Connect any WordPress form or event to 200+ apps — no code. Send leads, orders, and signups to your CRM, email, or sheets in minutes.
Lenix Leads Collector
lenix-elementor-leads-addon
Leads Collector, Collects forms entries from Elementor,Cf7,WPForms and more with export to CSV.
Contact Form to Any API
contact-form-to-any-api
Send Contact Form 7 submissions to any API, Webhook or CRM - quick setup, flexible payloads, endpoints and authentication.
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin
cf7-zoho
Send Contact Form 7, WPforms, Elementor, Formidable, Ninja Forms and many other contact form submissions to zoho CRM and Bigin.
Zoho CRM Lead Magnet
zoho-crm-forms
Websites are one of the most important sources of leads for your business.
Corymbus Forms Developer Profile
1 plugin · 10 total installs
How We Detect Corymbus Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/corymbus-forms/HTML / DOM Fingerprints
pagecontact.id<iframe src="https://srv.corymb.us/pages/ loading="lazy"