
Form1 Security & Risk Analysis
wordpress.org/plugins/form1お問合わせフォームを簡単に設置できます。確認画面付きで管理画面から履歴を管理できます。
Is Form1 Safe to Use in 2026?
Generally Safe
Score 85/100Form1 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "form1" v1.0.2 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has a history of zero known vulnerabilities, suggesting a potentially stable and well-maintained codebase. However, the static analysis reveals significant concerns, particularly with output escaping. A substantial portion of outputs (62%) are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with extreme care before being displayed. Furthermore, the taint analysis flags three critical severity flows with unsanitized paths, indicating potential security weaknesses where untrusted input might be processed in a dangerous way. While the plugin has entry points and nonce checks, the absence of capability checks on AJAX handlers is a notable omission, potentially allowing unauthorized users to trigger actions. The lack of known CVEs is a strength, but the identified code signals and taint flows suggest that inherent risks exist that have not yet been exploited or publicly disclosed.
Key Concerns
- High percentage of unescaped output
- Critical severity taint flows
- Missing capability checks on AJAX handlers
Form1 Security Vulnerabilities
Form1 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Form1 Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Form1 Maintenance & Trust
Maintenance Signals
Community Trust
Form1 Alternatives
Formzu WP
formzu-wp
メールフォーム無料作成サービス「フォームズ」のSSL通信フォームを簡単に設置できます。
FormToSS-フォムトス- | Contact Form 7 と スプレッドシート(スプシ)の連携をノーコードで!
form-to-ss
このプラグインは、Contact Form 7 のフォームデータを、自動的に Google スプレッドシートに送信します。
OS-WPカスタマイズプラグイン
os-wpc
OS-WPカスタマイズプラグインは、次のような機能があります。
Contact Form 7
contact-form-7
Just another contact form plugin. Simple but flexible.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
Form1 Developer Profile
2 plugins · 70 total installs
How We Detect Form1
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/form1/front.js//cdnjs.cloudflare.com/ajax/libs/uikit/2.23.0/js/uikit.min.js//ajaxzip3.github.io/ajaxzip3.jsform1/front.js?ver=HTML / DOM Fingerprints
uk-formuk-form-horizontaluk-form-rowuk-form-labeluk-form-controlsuk-form-controls-textuk-width-1-1uk-icon-check-circle-o+15 moreid="form1_form"id="zip_search"id="form1_modal"id="form1_btn_cancel"id="form1_btn_send"F1<form method="post" class="uk-form uk-form-horizontal" id="form1_form">