Receive Notifications After Form Submitting – Form Notify for Any Forms Security & Risk Analysis

wordpress.org/plugins/form-notify

⭐Description

30 active installs v1.1.08 PHP 8.0+ WP 4.8+ Updated Nov 26, 2024
line-loginline-messaging-apiline-notifysms
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Receive Notifications After Form Submitting – Form Notify for Any Forms Safe to Use in 2026?

Generally Safe

Score 92/100

Receive Notifications After Form Submitting – Form Notify for Any Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin 'form-notify' v1.1.08 exhibits a generally good security posture with several strong practices in place. The absence of known CVEs, unpatched vulnerabilities, and a clean vulnerability history are positive indicators. The plugin also demonstrates commendable use of prepared statements for all SQL queries and has a high percentage of properly escaped output, minimizing risks related to data injection and cross-site scripting. However, the presence of the `unserialize` function is a significant concern, as it can lead to object injection vulnerabilities if not handled with extreme caution and proper input sanitization. While no critical taint flows were identified in this analysis, the potential for misuse of unserialize remains a notable risk.

Key Concerns

  • Presence of unserialize function
Vulnerabilities
None known

Receive Notifications After Form Submitting – Form Notify for Any Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Receive Notifications After Form Submitting – Form Notify for Any Forms Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
9 prepared
Unescaped Output
20
148 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
13
Bundled Libraries
0

Dangerous Functions Found

unserialize$arr = implode( ',', unserialize( $value ) ); // phpcs:ignoresrc\Events\Gravity\Notify.php:38

SQL Query Safety

100% prepared9 total queries

Output Escaping

88% escaped168 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
set_logged_redirect (src\APIs\Line\Login\User.php:198)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Receive Notifications After Form Submitting – Form Notify for Any Forms Attack Surface

Entry Points7
Unprotected0

REST API Routes 6

GET/wp-json/form-notify/v1/loginsrc\APIs\Line\Login\Route.php:34
GET/wp-json/form-notify/v1/callbacksrc\APIs\Line\Login\Route.php:46
GET/wp-json/easygo/v1/get-pointssrc\APIs\Sms\Easygo.php:157
GET/wp-json/e8d/v1/get-pointssrc\APIs\Sms\Every8d.php:262
GET/wp-json/form-notify/v1/sms/callbacksrc\APIs\Sms\Mitake.php:133
GET/wp-json/mitake/v1/get-pointssrc\APIs\Sms\Mitake.php:147

Shortcodes 1

[form_notify_linelogin] src\APIs\Line\Login\Button.php:24
WordPress Hooks 49
actionplugin_loadedform-notify.php:44
actionadmin_initform-notify.php:63
actionwp_enqueue_scriptsform-notify.php:78
actionadmin_enqueue_scriptsform-notify.php:86
filterscript_loader_tagform-notify.php:93
actioninitform-notify.php:107
actionwp_enqueue_scriptssrc\APIs\Line\Login\Button.php:25
actionplugins_loadedsrc\APIs\Line\Login\Button.php:26
actionlogin_formsrc\APIs\Line\Login\Button.php:42
actionregister_formsrc\APIs\Line\Login\Button.php:43
actionlogin_enqueue_scriptssrc\APIs\Line\Login\Button.php:44
actionrest_api_initsrc\APIs\Line\Login\Route.php:24
actioninitsrc\APIs\Line\Login\User.php:38
actionwp_footersrc\APIs\Line\Login\User.php:39
actioninitsrc\APIs\Line\Login\User.php:40
filterpre_get_avatar_datasrc\APIs\Line\Login\User.php:41
actionadd_meta_boxessrc\APIs\Metabox\Metabox.php:75
actionsave_postsrc\APIs\Metabox\Metabox.php:76
actionadmin_enqueue_scriptssrc\APIs\Metabox\Metabox.php:77
actionrest_api_initsrc\APIs\Sms\Easygo.php:74
actionform_notify_action_module_type_eventssrc\APIs\Sms\Easygo.php:75
actionform_notify_action_module_type_eventssrc\APIs\Sms\Every8d.php:95
actionrest_api_initsrc\APIs\Sms\Every8d.php:96
actionrest_api_initsrc\APIs\Sms\Mitake.php:60
actionform_notify_action_module_type_eventssrc\APIs\Sms\Mitake.php:61
actionadmin_enqueue_scriptssrc\Assets.php:21
filterform_notify_trigger_event_optionssrc\Events\Elementor\Form.php:43
actionform_notify_triggersrc\Events\Elementor\Form.php:44
actionform_notify_paramsrc\Events\Elementor\Form.php:45
actionelementor_pro/forms/new_recordsrc\Events\Elementor\Form.php:46
actione8d_check_status_fluent_formsrc\Events\Elementor\Form.php:47
filterform_notify_trigger_event_optionssrc\Events\Fluent\Form.php:43
actionform_notify_triggersrc\Events\Fluent\Form.php:44
actionform_notify_paramsrc\Events\Fluent\Form.php:45
filterform_notify_action_modulesrc\Events\Fluent\Form.php:46
actionfluentform_submission_insertedsrc\Events\Fluent\Form.php:47
actione8d_check_status_fluent_formsrc\Events\Fluent\Form.php:48
filterform_notify_trigger_event_optionssrc\Events\Gravity\Form.php:43
actionform_notify_triggersrc\Events\Gravity\Form.php:44
actionform_notify_paramsrc\Events\Gravity\Form.php:45
actiongform_after_submissionsrc\Events\Gravity\Form.php:46
actione8d_check_status_gravity_formsrc\Events\Gravity\Form.php:47
actionadmin_menusrc\Options\History.php:32
filterset-screen-optionsrc\Options\History.php:33
actioninitsrc\Options\Option.php:25
actionplugins_loadedsrc\Posts\Notify\Cpt.php:26
actionadmin_initsrc\Posts\Notify\Metabox\Action.php:25
actionadmin_initsrc\Posts\Notify\Metabox\Param.php:25
actionadmin_initsrc\Posts\Notify\Metabox\Trigger.php:25
Maintenance & Trust

Receive Notifications After Form Submitting – Form Notify for Any Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 26, 2024
PHP min version8.0
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Receive Notifications After Form Submitting – Form Notify for Any Forms Developer Profile

Oberon Lai

1 plugin · 30 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Receive Notifications After Form Submitting – Form Notify for Any Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/form-notify/assets/dist/wp-content/plugins/form-notify/assets/src/alpine.js/wp-content/plugins/form-notify/assets/src/login.css/wp-content/plugins/form-notify/assets/img/dashicon.png/wp-content/plugins/form-notify/assets/img/icon-line.svg
Script Paths
/wp-content/plugins/form-notify/assets/dist/app.js/wp-content/plugins/form-notify/assets/dist/admin.js/wp-content/plugins/form-notify/assets/src/alpine.js
Version Parameters
form-notify/assets/dist?ver=form-notify/assets/src/alpine.js?ver=form-notify/assets/src/login.css?ver=

HTML / DOM Fingerprints

CSS Classes
form-notify-line-wrap
Data Attributes
data-wpackio-baseurl="/wp-content/plugins/form-notify/assets/dist"
JS Globals
lineLoginButtonParams
Shortcode Output
[form_notify_linelogin]
FAQ

Frequently Asked Questions about Receive Notifications After Form Submitting – Form Notify for Any Forms