
Form Generator for WordPress Security & Risk Analysis
wordpress.org/plugins/form-generator-powered-by-jotformForm Generator seamlessly delivers JotForm to your WordPress website.
Is Form Generator for WordPress Safe to Use in 2026?
Use With Caution
Score 63/100Form Generator for WordPress has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "form-generator-powered-by-jotform" plugin v1.52 presents a mixed security posture. While it demonstrates good practices by securing all identified entry points (AJAX handlers, REST API routes, shortcodes) with authentication or permission checks, and includes a reasonable percentage of prepared SQL statements, there are significant areas of concern. The presence of 11 dangerous function calls, particularly 'unserialize', is a red flag, as unserialization vulnerabilities can lead to remote code execution if not handled with extreme care. Furthermore, the taint analysis revealing 5 flows with unsanitized paths, although not classified as critical or high severity in this analysis, indicates potential weaknesses in input validation that could be exploited. The plugin's vulnerability history, featuring one medium severity Cross-Site Scripting (XSS) CVE with a recent disclosure date and still unpatched, further exacerbates these concerns, suggesting a pattern of input sanitization issues. While the plugin's robust authentication for its entry points is a strength, the identified code signals and taint flow issues, coupled with the unpatched XSS vulnerability, necessitate careful consideration.
Key Concerns
- Unpatched CVEs
- Flows with unsanitized paths
- Dangerous functions (unserialize)
- Output escaping below 100%
- SQL queries not fully prepared
- Bundled libraries (potential risks)
Form Generator for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Form Generator for WordPress <= 1.52 - Authenticated (Administrator+) Stored Cross-Site Scripting
Form Generator for WordPress Release Timeline
Form Generator for WordPress Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Form Generator for WordPress Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 33
Maintenance & Trust
Form Generator for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Form Generator for WordPress Alternatives
Contact Form Monster
contact-form-monster
Contact form plugin is a simple contact form builder tool, which allows the user to create and edit different contact forms.
Skyflow Forms – Contact Form Builder, Easy, Modern, and Responsive Form Builder
skyflow-forms
Lightweight drag-and-drop form builder for WordPress. Create contact forms, multi-column layouts, and manage submissions.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
metform
The most popular Elementor forms builder to create WordPress forms like contact forms, booking forms, feedback form, survey forms, application forms a …
Form Generator for WordPress Developer Profile
1 plugin · 200 total installs
How We Detect Form Generator for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/form-generator-powered-by-jotform/assets/css/bootstrap-responsive.min.css/wp-content/plugins/form-generator-powered-by-jotform/assets/css/bootstrap.min.css/wp-content/plugins/form-generator-powered-by-jotform/assets/css/jquery.datetimepicker.css/wp-content/plugins/form-generator-powered-by-jotform/assets/css/style.css/wp-content/plugins/form-generator-powered-by-jotform/assets/js/bootstrap-datepicker.js/wp-content/plugins/form-generator-powered-by-jotform/assets/js/bootstrap.min.js/wp-content/plugins/form-generator-powered-by-jotform/assets/js/jquery.datetimepicker.full.min.js/wp-content/plugins/form-generator-powered-by-jotform/assets/js/jquery.min.js+5 more/wp-content/plugins/form-generator-powered-by-jotform/assets/js/jquery.min.js/wp-content/plugins/form-generator-powered-by-jotform/assets/js/bootstrap.min.js/wp-content/plugins/form-generator-powered-by-jotform/assets/js/parsley.min.js/wp-content/plugins/form-generator-powered-by-jotform/assets/js/select2.min.js/wp-content/plugins/form-generator-powered-by-jotform/assets/js/jquery.datetimepicker.full.min.js/wp-content/plugins/form-generator-powered-by-jotform/assets/js/bootstrap-datepicker.js+3 moreform-generator-powered-by-jotform/assets/css/bootstrap-responsive.min.css?ver=form-generator-powered-by-jotform/assets/css/bootstrap.min.css?ver=form-generator-powered-by-jotform/assets/css/jquery.datetimepicker.css?ver=form-generator-powered-by-jotform/assets/css/style.css?ver=form-generator-powered-by-jotform/assets/js/bootstrap-datepicker.js?ver=form-generator-powered-by-jotform/assets/js/bootstrap.min.js?ver=form-generator-powered-by-jotform/assets/js/jquery.datetimepicker.full.min.js?ver=form-generator-powered-by-jotform/assets/js/jquery.min.js?ver=form-generator-powered-by-jotform/assets/js/main.js?ver=form-generator-powered-by-jotform/assets/js/numeral.min.js?ver=form-generator-powered-by-jotform/assets/js/parsley.min.js?ver=form-generator-powered-by-jotform/assets/js/select2.min.js?ver=form-generator-powered-by-jotform/inc/js/admin-script.js?ver=HTML / DOM Fingerprints
jotform-form-containerjotform-form-wrapper<!-- Powered by JotForm --><!-- Start JotForm embed code --><!-- End JotForm embed code -->data-form-iddata-form-tokenJotformEmbed JotformAPI[jotform-form-container][jotform-form-wrapper]