
Entries Display for WPForms Security & Risk Analysis
wordpress.org/plugins/entries-display-for-wpformsDisplay WPForms entries as beautifully styled comments with advanced typography controls. Perfect for testimonials, reviews, and feedback.
Is Entries Display for WPForms Safe to Use in 2026?
Generally Safe
Score 100/100Entries Display for WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "entries-display-for-wpforms" plugin version 0.4 presents a generally good security posture based on the static analysis. The plugin demonstrates strong adherence to secure coding practices by not utilizing any dangerous functions, performing all SQL queries using prepared statements, and including nonce checks for its single AJAX handler. There are also no known vulnerabilities (CVEs) associated with this plugin, which is a very positive indicator. However, a significant concern arises from the output escaping. With 163 total outputs and only 57% properly escaped, this leaves a considerable portion of the output potentially vulnerable to Cross-Site Scripting (XSS) attacks. The absence of capability checks on the AJAX handler, while mitigated by the presence of a nonce check, could still be a point of failure if the nonce check were to be bypassed or removed in a future update. Overall, while the lack of critical code flaws and vulnerability history is reassuring, the widespread potential for unescaped output is a notable weakness that requires attention.
Key Concerns
- Significant portion of output not properly escaped
- AJAX handler lacks capability checks
Entries Display for WPForms Security Vulnerabilities
Entries Display for WPForms Code Analysis
Output Escaping
Entries Display for WPForms Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Entries Display for WPForms Maintenance & Trust
Maintenance Signals
Community Trust
Entries Display for WPForms Alternatives
Views for WPForms – Display & Edit WPForms Entries on your site frontend
views-for-wpforms-lite
Display and Edit WPForms Entries Directly on Your Website with No Coding Knowledge Needed.
Page Builder for WPForms – Display your WPForms entries in any page
page-builder-for-wpforms
In a few clicks create listings, calendars, tables, confirmation pages or everything you need using your WPForms entries. No coding required.
Automation for WPForms
automation-for-wpforms
Create automatic actions using WPForms
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
Decent Comments
decent-comments
Decent Comments shows what people say. A more engaging way to show comments.
Entries Display for WPForms Developer Profile
1 plugin · 10 total installs
How We Detect Entries Display for WPForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/entries-display-for-wpforms/assets/css/frontend.csswpfed-frontend-stylesHTML / DOM Fingerprints
wpfed-entry-display