
gaplugin-form Security & Risk Analysis
wordpress.org/plugins/form-gaA form manager
Is gaplugin-form Safe to Use in 2026?
Generally Safe
Score 85/100gaplugin-form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "form-ga" plugin v0.01.00.00 presents a mixed security profile. On the positive side, it boasts a small attack surface with only one shortcode and no detected AJAX handlers, REST API routes, or cron events. The absence of external HTTP requests, file operations, and bundled libraries further contributes to a relatively lean codebase. However, significant concerns arise from the code analysis. All SQL queries are performed without prepared statements, which is a critical vulnerability that could lead to SQL injection. Furthermore, the lack of nonce checks and capability checks is alarming, as these are fundamental security mechanisms in WordPress to prevent Cross-Site Request Forgery and unauthorized actions. The taint analysis, while reporting no critical or high severity flows, does indicate that all analyzed flows had unsanitized paths, which is a precursor to potential vulnerabilities even if not immediately exploited in this specific version.
The vulnerability history is clean, with no recorded CVEs. While this is a positive indicator, it's important to note that "form-ga" is at a very early version (0.01.00.00), and the lack of vulnerabilities may simply be due to its immaturity and limited exposure rather than robust security practices. The primary risks stem from the fundamental security oversights in the code itself: the reliance on raw SQL and the complete absence of nonce and capability checks. These issues represent significant weaknesses that could be easily exploited in a production environment, even without a publicly known vulnerability history.
Key Concerns
- All SQL queries are not prepared
- No nonce checks found
- No capability checks found
- Unsanitized paths in all taint flows
gaplugin-form Security Vulnerabilities
gaplugin-form Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
gaplugin-form Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
gaplugin-form Maintenance & Trust
Maintenance Signals
Community Trust
gaplugin-form Alternatives
Contact Form 7
contact-form-7
Just another contact form plugin. Simple but flexible.
LiteSpeed Cache
litespeed-cache
All-in-one unbeatable acceleration & PageSpeed improvement: caching, image/CSS/JS optimization...
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Jetpack – WP Security, Backup, Speed, & Growth
jetpack
Improve your WP security with powerful one-click tools like backup, WAF, and malware scan. Includes free tools like stats, CDN and social sharing.
gaplugin-form Developer Profile
4 plugins · 0 total installs
How We Detect gaplugin-form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/form-ga/includes/FormGAP/admin_form_gap.css/wp-content/plugins/form-ga/includes/FormGAP/admin_form_gap_js.js/wp-content/plugins/form-ga/includes/FormGAP/colorPicker.js/wp-content/plugins/form-ga/includes/FormGAP/admin_form_gap_js.js/wp-content/plugins/form-ga/includes/FormGAP/colorPicker.jsHTML / DOM Fingerprints
formmaindata-tabgap