
Database Addon For WPForms ( wpforms entries ) – WPFormsDB Security & Risk Analysis
wordpress.org/plugins/database-for-wpformsSave and manage WPForms entries (WPForms database). It is a lightweight WPForms database plugin.
Is Database Addon For WPForms ( wpforms entries ) – WPFormsDB Safe to Use in 2026?
Generally Safe
Score 100/100Database Addon For WPForms ( wpforms entries ) – WPFormsDB has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "database-for-wpforms" v1.1.0 exhibits a generally good security posture with a zero-attack surface for entry points like AJAX, REST API, and shortcodes. The absence of known CVEs and a clean vulnerability history are positive indicators. However, the presence of 8 instances of the "unserialize" function is a significant concern, as unserialization of untrusted data is a common vector for remote code execution vulnerabilities. While the taint analysis didn't flag critical or high severity issues in the analyzed flows, the "unsanitized paths" flow suggests potential for unexpected behavior if data is not handled meticulously throughout the application. The SQL query preparedness rate of 29% is also concerning, indicating a reliance on raw SQL queries that could be susceptible to SQL injection if input is not properly sanitized and validated before being used in these queries.
Overall, the plugin demonstrates strengths in its limited attack surface and clean history. Nevertheless, the identified "unserialize" usage and the lower-than-ideal prepared statement usage for SQL queries present notable risks that require careful attention and mitigation. The plugin would benefit from a thorough review of all "unserialize" calls and improved practices for SQL query construction to further enhance its security.
Key Concerns
- Dangerous function: unserialize used 8 times
- Low SQL prepared statement usage (29%)
- Taint flow with unsanitized paths
Database Addon For WPForms ( wpforms entries ) – WPFormsDB Security Vulnerabilities
Database Addon For WPForms ( wpforms entries ) – WPFormsDB Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Database Addon For WPForms ( wpforms entries ) – WPFormsDB Attack Surface
WordPress Hooks 6
Maintenance & Trust
Database Addon For WPForms ( wpforms entries ) – WPFormsDB Maintenance & Trust
Maintenance Signals
Community Trust
Database Addon For WPForms ( wpforms entries ) – WPFormsDB Alternatives
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR)
contact-form-7-image-captcha
Adds an Image CAPTCHA to Contact Form 7 and WPForms, GDPR ready, perfect WPForms or Contact Form 7 Spam Protection Image CAPTCHA, adds a honeypot
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
Utimate Kit ( Styler ) for WPForms
styler-for-wpforms
Ultimate Kit for WPForms makes the task of designing WPForms an easy one.
GSheetConnector For WPForms – WPForms Google Sheets Integration (Real-Time Sync)
gsheetconnector-wpforms
Connect WPForms to Google Sheets and automatically send form entries to a google sheet in real-time. No manual exports, no coding required.
Tablesome Table – Contact Form DB – WPForms, CF7, Gravity, Forminator, Fluent
tablesome
Powerful Table, Form & Mail Automations. Form Entry Management (+ frontend table ), integrate with MailChimp, G Sheets, CF7, WPForms, Elementor, etc.
Database Addon For WPForms ( wpforms entries ) – WPFormsDB Developer Profile
9 plugins · 23K total installs
How We Detect Database Addon For WPForms ( wpforms entries ) – WPFormsDB
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/database-for-wpforms/css/wpforms-db-style.css/wp-content/plugins/database-for-wpforms/js/wpforms-db.js/wp-content/plugins/database-for-wpforms/js/wpforms-db.jsdatabase-for-wpforms/css/wpforms-db-style.css?ver=database-for-wpforms/js/wpforms-db.js?ver=HTML / DOM Fingerprints
wpforms-db-table-wrapwpforms-db-form-titlewpforms-db-status-unreadwpforms-db-form-datedata-form-iddata-noncewpforms_db_ajax_obj