FlowForms – Conversational Form Builder for WordPress Security & Risk Analysis

wordpress.org/plugins/flowforms

The Typeform alternative for WordPress. Build beautiful, conversational step-by-step forms, surveys & quizzes — self-hosted, free, no monthly fees.

0 active installs v1.0.0 PHP 7.4+ WP 6.2+ Updated Apr 14, 2026
contact-formconversational-formform-buildersurveytypeform
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FlowForms – Conversational Form Builder for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

FlowForms – Conversational Form Builder for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The Flowforms plugin v1.0.0 exhibits a generally good security posture, with notable strengths in its adherence to secure coding practices. The plugin utilizes prepared statements exclusively for its SQL queries and properly escapes all output, which significantly mitigates the risk of SQL injection and cross-site scripting (XSS) vulnerabilities. The extensive use of nonce and capability checks across its entry points further enhances its defenses against unauthorized access and actions. The absence of known CVEs and a clean vulnerability history are strong indicators of the developers' commitment to security.

Despite these strengths, the taint analysis reveals a potential area of concern. Four out of seven analyzed flows have unsanitized paths, with two identified as high severity. While the static analysis doesn't explicitly detail the nature of these unsanitized paths, they represent the most significant risk within this version. This suggests that user-supplied data might be processed in a way that could lead to vulnerabilities if not handled meticulously within the plugin's logic. The total absence of file operations and external HTTP requests is a positive aspect, removing common attack vectors.

In conclusion, Flowforms v1.0.0 is a relatively secure plugin due to its solid foundation in prepared statements, output escaping, and robust authentication checks. However, the high-severity taint flows demand careful investigation and remediation to ensure that unsanitized data handling is fully addressed. Addressing these specific taint flows will further solidify the plugin's security.

Key Concerns

  • High severity taint flows found
  • Unsanitized paths in taint flows
Vulnerabilities
None known

FlowForms – Conversational Form Builder for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

FlowForms – Conversational Form Builder for WordPress Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

FlowForms – Conversational Form Builder for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
18 prepared
Unescaped Output
0
373 escaped
Nonce Checks
12
Capability Checks
33
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared18 total queries

Output Escaping

100% escaped373 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

7 flows4 with unsanitized paths
handle_preview (includes/frontend/class-frontend.php:374)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FlowForms – Conversational Form Builder for WordPress Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_flowforms_toggle_starincludes/admin/entries/class-entries-overview.php:56

Shortcodes 1

[flowform] includes/frontend/class-frontend.php:41
WordPress Hooks 32
actionplugins_loadedincludes/FlowForms.php:73
actioninitincludes/admin/block/class-block.php:19
actionenqueue_block_editor_assetsincludes/admin/block/class-block.php:35
actionadmin_initincludes/admin/builder/class-builder.php:54
actionadmin_initincludes/admin/builder/class-builder.php:55
actionadmin_headincludes/admin/builder/class-builder.php:117
actionadmin_enqueue_scriptsincludes/admin/builder/class-builder.php:118
actionflowforms_admin_pageincludes/admin/builder/class-builder.php:119
actionadmin_menuincludes/admin/class-menu.php:15
actionadmin_initincludes/admin/class-settings.php:29
actionflowforms_admin_pageincludes/admin/class-settings.php:56
actionflowforms_admin_pageincludes/admin/class-settings.php:183
filterset-screen-optionincludes/admin/entries/class-entries-overview.php:58
actionadmin_initincludes/admin/entries/class-entries-overview.php:60
actionload-flowforms_page_flowforms_entriesincludes/admin/entries/class-entries-overview.php:88
actioncurrent_screenincludes/admin/entries/class-entries-overview.php:89
actionadmin_enqueue_scriptsincludes/admin/entries/class-entries-overview.php:90
actionflowforms_admin_pageincludes/admin/entries/class-entries-overview.php:91
actionadmin_initincludes/admin/forms/class-forms-overview.php:37
actionload-toplevel_page_flowforms_formsincludes/admin/forms/class-forms-overview.php:52
actioncurrent_screenincludes/admin/forms/class-forms-overview.php:57
actionadmin_enqueue_scriptsincludes/admin/forms/class-forms-overview.php:58
actionflowforms_admin_pageincludes/admin/forms/class-forms-overview.php:59
filterset_screen_option_flowforms_forms_per_pageincludes/admin/forms/class-forms-overview.php:76
filterwp_untrash_post_statusincludes/admin/forms/class-forms-overview.php:209
actioninitincludes/class-form.php:23
actionbefore_delete_postincludes/class-form.php:26
actionrest_api_initincludes/class-rest-api.php:14
actionwp_enqueue_scriptsincludes/frontend/class-frontend.php:44
actioninitincludes/frontend/class-frontend.php:46
actiontemplate_redirectincludes/frontend/class-frontend.php:47
actiontemplate_redirectincludes/frontend/class-frontend.php:48
Maintenance & Trust

FlowForms – Conversational Form Builder for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 14, 2026
PHP min version7.4
Downloads113

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

FlowForms – Conversational Form Builder for WordPress Developer Profile

Priyanshu Chaudhary

2 plugins · 700 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FlowForms – Conversational Form Builder for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flowforms/build/builder/index.js/wp-content/plugins/flowforms/build/builder/style-index.css
Script Paths
/wp-content/plugins/flowforms/build/builder/index.js
Version Parameters
flowforms/build/builder/index.js?ver=flowforms/build/builder/style-index.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpff-page-loaderwpff-loader-contentwpff-loader-logowpff-loader-spinner
HTML Comments
<!-- FlowForms WordPress Plugin -->
Data Attributes
aria-hiddenroleid
JS Globals
flowformsBuilderData
FAQ

Frequently Asked Questions about FlowForms – Conversational Form Builder for WordPress