
Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database Security & Risk Analysis
wordpress.org/plugins/form-vibesSave Contact Form 7, Elementor, WPForms & Gravity Forms entries in database. View, filter, export form submissions to CSV & analytics reports.
Is Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database Safe to Use in 2026?
Generally Safe
Score 90/100Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "form-vibes" v1.5.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in output escaping, with 100% of outputs being properly escaped, and a high percentage (84%) of SQL queries utilizing prepared statements. Furthermore, all identified AJAX entry points have been secured with authorization checks, and there are no shortcodes, cron events, or REST API routes that present an immediate attack surface without proper permission callbacks. The plugin also correctly implements nonce checks and capability checks for many of its operations.
However, several areas raise significant concerns. The presence of a dangerous `unserialize` function, even if not directly linked to a critical taint flow in the static analysis, is a known vector for remote code execution vulnerabilities if user-controlled data is involved. The taint analysis revealed two high-severity flows with unsanitized paths, indicating potential for injection-like vulnerabilities. The plugin's history of four known CVEs, including two high-severity ones for "Missing Authorization" and "SQL Injection," is particularly worrying. While there are no currently unpatched CVEs, the recurring nature of these vulnerability types suggests underlying architectural weaknesses that may not be fully addressed.
In conclusion, while "form-vibes" v1.5.2 has implemented several security best practices, the identified dangerous function, high-severity taint flows, and a history of critical vulnerability types warrant caution. The plugin's strengths lie in its output escaping and secure AJAX handling, but the potential for injection and deserialization vulnerabilities, coupled with its past vulnerability record, necessitates careful monitoring and potential mitigation efforts.
Key Concerns
- High severity taint flows
- Dangerous function: unserialize
- History of High severity CVEs (2)
- History of Medium severity CVEs (2)
- Taint flows with unsanitized paths (3)
- Bundled library: Guzzle
Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Form Vibes <= 1.5.2 - Unauthenticated Stored Cross-Site Scripting via Contact Form 7 Form Field
Form Vibes – Database Manager for Forms <= 1.4.13 - Authenticated (Admin+) SQL Injection
Form Vibes – Database Manager for Forms <= 1.4.12 - Missing Authorization in Multiple Functions
Form Vibes <= 1.4.10 - Authenticated (Subscriber+) SQL Injection via fv_export_data
Form Vibes <= 1.4.5 - Authenticated (Admininstrator+) SQL Injection
Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database Release Timeline
Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database Attack Surface
AJAX Handlers 9
WordPress Hooks 61
Maintenance & Trust
Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database Maintenance & Trust
Maintenance Signals
Community Trust
Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database Alternatives
FormsDB – Save Elementor Forms to Google Sheets & Post Type
sb-elementor-contact-form-db
Connect Elementor forms with Google Sheets to sync form entries, or save form submissions in any post type using Elementor Pro or Hello Plus forms.
Advanced Contact form 7 DB
advanced-cf7-db
Save all contact form 7 form submitted data to the database, View, Ordering, Change field labels and Import/Export data using CSV.
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection)
extensions-for-cf7
Easily save contact form data, apply conditional logic in the fields and redirect to any page after contact form submission.
Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database Developer Profile
12 plugins · 191K total installs
How We Detect Form Vibes – Save Contact Form 7 & Elementor Form Entries to Database
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/form-vibes/assets/css/fv-admin.css/wp-content/plugins/form-vibes/assets/css/fv-common.css/wp-content/plugins/form-vibes/assets/js/fv-admin.js/wp-content/plugins/form-vibes/assets/js/fv-common.js/wp-content/plugins/form-vibes/assets/js/fv-admin.js/wp-content/plugins/form-vibes/assets/js/fv-common.jsform-vibes/assets/css/fv-admin.css?ver=form-vibes/assets/css/fv-common.css?ver=form-vibes/assets/js/fv-admin.js?ver=form-vibes/assets/js/fv-common.js?ver=HTML / DOM Fingerprints
fv-admin-wrapperfv-admin-contentfv-leads-tablefv-settings-wrapForm Vibes Admin Wrapper StartForm Vibes Admin Content StartForm Vibes Admin Content EndForm Vibes Admin Wrapper Enddata-fv-form-iddata-fv-field-namefv_admin_paramsfv_common_paramsFormVibes/wp-json/formvibes/v1/leads/wp-json/formvibes/v1/settings