
Formidable Forms Posts, Pages and CPT Field Type Security & Risk Analysis
wordpress.org/plugins/ff-posts-pages-and-cpt-field-typeAdds a new field type to Formidable Forms allowing the user to choose a post, page or CPT
Is Formidable Forms Posts, Pages and CPT Field Type Safe to Use in 2026?
Generally Safe
Score 85/100Formidable Forms Posts, Pages and CPT Field Type has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the 'ff-posts-pages-and-cpt-field-type' plugin v1.0.0 exhibits a strong security posture in several key areas. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code signals are generally positive, with no dangerous functions, no raw SQL queries (all using prepared statements), and a high percentage of properly escaped output. The lack of file operations, external HTTP requests, and a reported zero history of vulnerabilities further reinforces this perception of good security practices.
However, the analysis does highlight some areas that, while not presenting immediate critical risks based on the provided data, warrant caution and future attention. The complete absence of nonce checks and capability checks across all entry points (even though the entry points themselves are zero) is a notable concern. While there are currently no reported vulnerabilities or taint flows, this lack of explicit authorization and integrity checks could become a significant vulnerability if the plugin's functionality expands or if unforeseen attack vectors are discovered. The plugin's strengths lie in its limited attack surface and secure data handling practices, but the oversight in authorization checks presents a potential weakness.
In conclusion, the plugin appears to be developed with security in mind, demonstrating secure coding practices like prepared statements and output escaping. The lack of historical vulnerabilities is a positive indicator. Nevertheless, the absence of nonce and capability checks represents a structural weakness that, while not exploited in the current version or historical context, could be a point of concern for future development or in different usage scenarios. It's recommended to implement these checks as the plugin evolves.
Key Concerns
- Missing nonce checks
- Missing capability checks
Formidable Forms Posts, Pages and CPT Field Type Security Vulnerabilities
Formidable Forms Posts, Pages and CPT Field Type Code Analysis
Output Escaping
Formidable Forms Posts, Pages and CPT Field Type Attack Surface
WordPress Hooks 3
Maintenance & Trust
Formidable Forms Posts, Pages and CPT Field Type Maintenance & Trust
Maintenance Signals
Community Trust
Formidable Forms Posts, Pages and CPT Field Type Alternatives
WP Contact Slider – Contact Form Slider Widget
wp-contact-slider
Helps you to show slide out contact form to display CF7, Gravity forms, Ninja Forms, WP Forms, display random text/HTML and support some other forms.
BSK Forms Blacklist
bsk-gravityforms-blacklist
Checks field content and block submitting base on your keywords. Blocking IP, Country is only supported in the Pro version.
Formidable Forms Signature Online Contract Automation
forms-signature-formidable-online-contract-automation
Instantly produce a legally enforceable & court recognized contract from a Formidable Forms submission. Legal contracts. UETA/ESIGN Compliant.
Formidable Forms + Sprout Invoices – Easy Invoice & Estimate Submissions
sprout-invoices-formidable-forms
Dynamic invoicing (and estimates/quotes) from Formidable Form submissions.
WP Mautic Form Integrator
wp-mautic-form-integrator
Mautic is a marketing automation software and WP Mautic Form Integrator plugin is a bridge between Mautic and several highly used form plugins.
Formidable Forms Posts, Pages and CPT Field Type Developer Profile
8 plugins · 7K total installs
How We Detect Formidable Forms Posts, Pages and CPT Field Type
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ff-posts-pages-and-cpt-field-type/HTML / DOM Fingerprints
frm_icon_fontfrm_caret-square-down_icondata-field-idFPPCPTFT<select name="field_options[post_types_.*?]" multiple id="post_types_.*?"><input name="field_options[value_format_.*?]" id="value_format_.*?"<div class="howto">Possible Values: %id% %title% %meta_{meta_key} %taxonomy_{taxonomy}</div><input name="field_options[label_format_.*?]" id="label_format_.*?"