
Form Block Security & Risk Analysis
wordpress.org/plugins/form-blockAn extensive yet user-friendly form block.
Is Form Block Safe to Use in 2026?
Generally Safe
Score 94/100Form Block has a strong security track record. Known vulnerabilities have been patched promptly.
The "form-block" plugin v1.7.1 presents a mixed security posture. On one hand, the static analysis shows a remarkably small attack surface with no discernible entry points and a complete absence of dangerous functions, SQL queries requiring sanitization, file operations, external requests, and crucially, no raw SQL queries or critical taint flows. This indicates a strong adherence to secure coding practices in these specific areas. However, a significant concern arises from the complete lack of output escaping and the absence of nonce and capability checks on all potential entry points, despite their apparent zero count in the static analysis. This suggests that while there may not be direct vulnerabilities exposed, any future expansion or modification of the plugin without implementing proper output escaping and access controls could lead to severe security flaws.
Key Concerns
- No output escaping implemented
- No nonce checks
- No capability checks
- Vulnerability history indicates past critical issues
Form Block Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Form Block <= 1.5.5 - Unauthenticated Arbitrary File Upload
Form Block <= 1.0.1 - Cross-Site Request Forgery
Form Block Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Form Block Attack Surface
Maintenance & Trust
Form Block Maintenance & Trust
Maintenance Signals
Community Trust
Form Block Alternatives
Form Builder Blocks
ninja-chandel-form-builder-blocks
Build powerful, custom forms directly inside the WordPress Block Editor with drag-and-drop ease and built-in entry management.
CF block
contact-block
CF Block is a custom Gutenberg Block That has the following upgradation to be followed they are
Advanced Editor Tools
tinymce-advanced
Extends and enhances the block editor (Gutenberg) and the classic editor (TinyMCE).
JetFormBuilder — Dynamic Blocks Form Builder
jetformbuilder
Advanced form builder plugin for Gutenberg. Create forms from the ground up, customize the existing ones, and style them up – all in one editor.
Contact Form 7: Accessible Defaults
contact-form-7-accessible-defaults
Replaces the default Contact Form 7 form with an accessible equivalent and provides a suite of selectable base forms.
Form Block Developer Profile
4 plugins · 14K total installs
How We Detect Form Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/form-block/assets/style/build/admin.css/wp-content/plugins/form-block/assets/js/tabs.js/wp-content/plugins/form-block/assets/js/snackbar.js/wp-content/plugins/form-block/assets/js/submissions.js/wp-content/plugins/form-block/assets/style/build/admin.min.css/wp-content/plugins/form-block/assets/js/build/tabs.min.js/wp-content/plugins/form-block/assets/js/build/snackbar.min.js/wp-content/plugins/form-block/assets/js/build/submissions.min.js/wp-content/plugins/form-block/assets/js/build/tabs.js/wp-content/plugins/form-block/assets/js/build/snackbar.js/wp-content/plugins/form-block/assets/js/build/submissions.jsform-block-admin?ver=form-block-admin-tabs?ver=form-block-admin-snackbar?ver=form-block-admin-submissions?ver=HTML / DOM Fingerprints
form-block-admin-snackbardata-form-block-noncedata-form-block-rest-urlformBlockSubmissions/wp-json/form-block/v1/submissions