
Form Submission Email Reports Security & Risk Analysis
wordpress.org/plugins/form-submission-reportsA lightweight plugin that retrieves form submission data from popular form plugins and emails scheduled reports (daily, weekly, and monthly).
Is Form Submission Email Reports Safe to Use in 2026?
Generally Safe
Score 100/100Form Submission Email Reports has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "form-submission-reports" plugin version 1.8 exhibits a generally strong security posture based on the static analysis. The complete absence of unprotected AJAX handlers, REST API routes, and shortcodes is a significant positive, drastically reducing the external attack surface. Furthermore, the consistent use of prepared statements for all SQL queries and a high percentage of properly escaped output demonstrates good coding practices for preventing common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS). The plugin also correctly implements nonce and capability checks for its limited entry points.
However, one concerning aspect identified in the taint analysis is a flow with an unsanitized path, flagged as high severity. While the static analysis does not detail the exact nature of this unsanitized path, it represents a potential risk for directory traversal or other path manipulation attacks, especially given it's the only high-severity finding. The presence of one file operation, while not inherently dangerous, warrants attention in conjunction with the unsanitized path to ensure it's not being exploited.
The plugin's vulnerability history, showing zero recorded CVEs, is excellent and suggests a historically secure development process. However, this lack of history, combined with the single high-severity taint flow, means this potential vulnerability should be treated with higher suspicion as it might be an undiscovered issue. Overall, the plugin is well-developed with strong preventative measures in place, but the high-severity taint flow requires immediate investigation and remediation to maintain a robust security profile.
Key Concerns
- High severity unsanitized path in taint analysis
Form Submission Email Reports Security Vulnerabilities
Form Submission Email Reports Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Form Submission Email Reports Attack Surface
WordPress Hooks 13
Scheduled Events 3
Maintenance & Trust
Form Submission Email Reports Maintenance & Trust
Maintenance Signals
Community Trust
Form Submission Email Reports Alternatives
WeekSync Scheduler
week-sync-scheduler
Automatically send weekly Gravity Forms entries reports via email with configurable schedule, recipients, and form selection.
WP All Export – Drag & Drop Export to Any Custom CSV, XML & Excel
wp-all-export
Easily export data from any post type, custom field, or taxonomy to a CSV, XML, or Excel file of any custom format. Supports WooCommerce products, ord …
WP All Export – Product Export Add-On for WooCommerce
product-export-for-woocommerce
Drag & drop to export products to CSV, Excel, or XML files of any format. Supports variations, images, attributes, brands, and more with powerful …
Export All Posts, Products, Orders, Refunds & Users
wp-ultimate-exporter
Export any WordPress website including WooCommerce data seamlessly with our powerful export plugin. Save records as CSV, XML, or Excel file for secure …
Export Plugin Details
export-plugin-details
Simple way to export your installed plugins list in CSV format.
Form Submission Email Reports Developer Profile
4 plugins · 90 total installs
How We Detect Form Submission Email Reports
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/form-submission-reports/css/setting.css