
فرم ساز فرم افزار Security & Risk Analysis
wordpress.org/plugins/formafzarابزاری آسان برای ساخت فرمهای آنلاین قدرتمند بصورت حرفهای، به آسانی و کمتر از چند دقیقه فرم خودتون رو بسازید و به اشتراک بگذارید
Is فرم ساز فرم افزار Safe to Use in 2026?
Generally Safe
Score 91/100فرم ساز فرم افزار has a strong security track record. Known vulnerabilities have been patched promptly.
The 'formafzar' plugin v2.1 exhibits a generally good security posture based on static analysis. The absence of dangerous functions, the complete use of prepared statements for SQL queries, and the proper escaping of all output are strong indicators of secure coding practices. Furthermore, the plugin's attack surface is minimal, consisting solely of a single shortcode, and no unauthenticated entry points were identified. File operations and external HTTP requests are also absent, reducing potential avenues for attack.
However, the plugin's vulnerability history presents a significant concern. It has one known CVE, though it is currently marked as unpatched, and the vulnerability type was Cross-Site Scripting (XSS), which can be severe. The fact that the last vulnerability was very recent (2025-01-07) suggests a pattern of past security flaws. While the static analysis shows no current XSS or taint flows, the historical data strongly implies that the plugin may have had vulnerabilities in the past, and there's a risk of such issues re-emerging if not diligently maintained.
In conclusion, while the current code appears robust against common web vulnerabilities, the historical presence of an unpatched XSS vulnerability is a critical weakness. Users should be aware of this past issue and ensure they are on the absolute latest version of the plugin if an update has been released to address it. The plugin's strengths lie in its secure coding practices for SQL and output, but the historical vulnerability trend warrants caution.
Key Concerns
- Unpatched CVE exists
- Past XSS vulnerability in history
- No nonce checks found
فرم ساز فرم افزار Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
formafzar <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
فرم ساز فرم افزار Code Analysis
Output Escaping
فرم ساز فرم افزار Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
فرم ساز فرم افزار Maintenance & Trust
Maintenance Signals
Community Trust
فرم ساز فرم افزار Alternatives
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
SureForms – Contact Form, Payment Form & Other Custom Form Builder
sureforms
The most beginner-friendly, AI Form Builder for WordPress to create contact forms, payment forms & other custom forms with advanced features, with …
Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform
embed-form
Create and embed secure online forms in WordPress using Jotform’s drag-and-drop builder, with PCI and HIPAA compliance and full data-security support.
Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder
gutena-forms
WordPress form builder to create lightweight contact forms, survey forms, feedback forms, booking forms, etc., right inside the Gutenberg editor.
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms
happyforms
Best WordPress contact form, newsletter form and payment form builder without the sucky stuff — lost emails, pesky spam, leaky privacy and outsourced …
فرم ساز فرم افزار Developer Profile
1 plugin · 600 total installs
How We Detect فرم ساز فرم افزار
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formafzar/formafzar-block.jshttps://formafzar.ir/pages/formbuilder/ravesh-formbuilder.jsHTML / DOM Fingerprints
START---- FORMAFZAR FORM BUILDER ---- formafzar.ir ----->END--- FORMAFZAR FORM BUILDER ---- formafzar.ir ----->form-urlform-styleform-link-textform-themeform-button-colorform-button-iconRaveshFormPathRaveshFormLangRaveshFormIsCRMRaveshFormIsFormican<script type="text/javascript" src="https://formafzar.ir/pages/formbuilder/ravesh-formbuilder.js"<a href="" target="_blank"