
Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform Security & Risk Analysis
wordpress.org/plugins/embed-formCreate and embed secure online forms in WordPress using Jotform’s drag-and-drop builder, with PCI and HIPAA compliance and full data-security support.
Is Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform Safe to Use in 2026?
Generally Safe
Score 99/100Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform has a strong security track record. Known vulnerabilities have been patched promptly.
The "embed-form" plugin v1.3.9 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by using prepared statements for all SQL queries, properly escaping all output, and having no file operations or external HTTP requests. The static analysis did not reveal any critical or high severity taint flows, suggesting that direct injection vulnerabilities are not immediately apparent in the analyzed code paths.
However, there are notable concerns. The plugin has a relatively small attack surface with only two entry points, but one of these entry points, an AJAX handler, lacks authentication checks. This unprotected AJAX handler is a significant risk, as it could be exploited by unauthenticated users. Furthermore, the plugin has a history of known vulnerabilities, including a medium-severity Cross-Site Scripting (XSS) flaw discovered in April 2024. While this specific vulnerability is currently unpatched, its presence indicates potential weaknesses in input sanitization or output encoding, even if not evident in the current static analysis. The absence of nonce checks on the unprotected AJAX handler further exacerbates this risk.
In conclusion, while the plugin exhibits some strong security foundations, the unprotected AJAX handler and its history of XSS vulnerabilities are serious concerns that outweigh the positive aspects. The lack of authentication on an entry point creates a direct path for potential attacks, and the past vulnerability suggests a pattern that needs careful monitoring and remediation.
Key Concerns
- AJAX handler without authentication checks
- Missing nonce checks on AJAX
- Known medium severity vulnerability (XSS)
Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Jotform Online Forms <= 1.3.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform Code Analysis
Output Escaping
Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform Maintenance & Trust
Maintenance Signals
Community Trust
Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform Alternatives
Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder
gutena-forms
WordPress form builder to create lightweight contact forms, survey forms, feedback forms, booking forms, etc., right inside the Gutenberg editor.
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms
happyforms
Best WordPress contact form, newsletter form and payment form builder without the sucky stuff — lost emails, pesky spam, leaky privacy and outsourced …
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
forminator
Best WordPress form builder plugin. Create contact forms, payment forms & order forms with 1000+ integrations.
Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform Developer Profile
3 plugins · 25K total installs
How We Detect Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/embed-form/jotform-wp-embed-fp-wrapper.js/wp-content/plugins/embed-form/jotform-wp-embed.jsjotform-wp-embed-fp-wrapper.js?ver=1.3.9HTML / DOM Fingerprints
JotFormWPEmbed<script type="text/javascript" src="//www.jotform.com/jsform/?redirect=1"></script>