
Embed PDF for WPForms Security & Risk Analysis
wordpress.org/plugins/embed-pdf-wpformsAn add-on for WPForms. Provides a PDF Viewer field.
Is Embed PDF for WPForms Safe to Use in 2026?
Generally Safe
Score 98/100Embed PDF for WPForms has a strong security track record. Known vulnerabilities have been patched promptly.
The 'embed-pdf-wpforms' plugin version 1.1.6 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, properly prepared SQL queries, and a high percentage of properly escaped output are positive indicators. Furthermore, the plugin implements both nonce and capability checks, and its attack surface appears to be well-protected with no unprotected entry points. The lack of file operations and external HTTP requests also reduces the potential for certain types of vulnerabilities.
However, the plugin's vulnerability history presents a significant concern. It has a known, albeit patched, high-severity vulnerability related to 'Unrestricted Upload of File with Dangerous Type'. While this vulnerability is currently unpatched, the presence of such a severe issue in its history suggests that the developers have had to address critical security flaws in the past, which could indicate underlying architectural weaknesses or a history of less stringent security practices. The fact that a high severity vulnerability existed is a strong indicator that past versions were indeed vulnerable and that vigilance is required.
In conclusion, while version 1.1.6 of 'embed-pdf-wpforms' demonstrates good static security practices for its current codebase, its past high-severity vulnerability warrants caution. The focus on securing the current attack surface is commendable, but the historical precedent of a severe vulnerability like unrestricted file uploads should not be overlooked when considering its overall risk.
Key Concerns
- History of high severity vulnerability
Embed PDF for WPForms Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Embed PDF for WPForms <= 1.1.5 - Authenticated (Subscriber+) Arbitrary File Upload
Embed PDF for WPForms Code Analysis
Output Escaping
Embed PDF for WPForms Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
Embed PDF for WPForms Maintenance & Trust
Maintenance Signals
Community Trust
Embed PDF for WPForms Alternatives
PDF Builder for WPForms
pdf-builder-for-wpforms
The first and only PDF drag and drop builder for WPForms.
PDF for WPForms + Drag and Drop Template Builder
pdf-for-wpforms
The plugin helps you create PDF for WPForms you can builder PDF template
WP Forms Signature Contract Add-On
wp-forms-signature-contract-add-on
Instantly produce a legally binding PDF WordPress contract from a WP Forms contact form submission. Digital Signature Pad. Proposal.
PDF Forms Filler for WPForms
pdf-forms-for-wpforms
Build WPForms from PDF forms. Get PDFs filled automatically and attached to email messages and/or website responses on form submissions.
PDF Importer for WPForms
pdf-importer-for-wpform
Import a pdf, map it to a form and attaching to any email
Embed PDF for WPForms Developer Profile
11 plugins · 7K total installs
How We Detect Embed PDF for WPForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/embed-pdf-wpforms/js/pdfjs/pdf.min.js/wp-content/plugins/embed-pdf-wpforms/js/pdfjs/pdf.worker.min.js/wp-content/plugins/embed-pdf-wpforms/js/field-pdf-viewer.js/wp-content/plugins/embed-pdf-wpforms/js/field-pdf-viewer.min.js/wp-content/plugins/embed-pdf-wpforms/js/form-editor.js/wp-content/plugins/embed-pdf-wpforms/js/form-editor.min.jsembed-pdf-wpforms/js/pdfjs/pdf.min.js?ver=embed-pdf-wpforms/js/field-pdf-viewer.js?ver=embed-pdf-wpforms/js/form-editor.js?ver=HTML / DOM Fingerprints
data-pdf-urldata-initial-scaleepdf_wf_pdfjs_stringsepdf_wf_pdf_viewer_stringsepdf_wf_form_editor_strings