فرم ساز فرم افزار Security & Risk Analysis

wordpress.org/plugins/formafzar

ابزاری آسان برای ساخت فرم‌های آنلاین قدرتمند بصورت حرفه‌ای، به آسانی و کمتر از چند دقیقه فرم خودتون رو بسازید و به اشتراک بگذارید

600 active installs v2.1 PHP + WP 2.8+ Updated Jan 11, 2025
custom-formsform-builderform-pluginformswordpress-contact-form
91
A · Safe
CVEs total1
Unpatched0
Last CVEJan 7, 2025
Safety Verdict

Is فرم ساز فرم افزار Safe to Use in 2026?

Generally Safe

Score 91/100

فرم ساز فرم افزار has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 7, 2025Updated 1yr ago
Risk Assessment

The 'formafzar' plugin v2.1 exhibits a generally good security posture based on static analysis. The absence of dangerous functions, the complete use of prepared statements for SQL queries, and the proper escaping of all output are strong indicators of secure coding practices. Furthermore, the plugin's attack surface is minimal, consisting solely of a single shortcode, and no unauthenticated entry points were identified. File operations and external HTTP requests are also absent, reducing potential avenues for attack.

However, the plugin's vulnerability history presents a significant concern. It has one known CVE, though it is currently marked as unpatched, and the vulnerability type was Cross-Site Scripting (XSS), which can be severe. The fact that the last vulnerability was very recent (2025-01-07) suggests a pattern of past security flaws. While the static analysis shows no current XSS or taint flows, the historical data strongly implies that the plugin may have had vulnerabilities in the past, and there's a risk of such issues re-emerging if not diligently maintained.

In conclusion, while the current code appears robust against common web vulnerabilities, the historical presence of an unpatched XSS vulnerability is a critical weakness. Users should be aware of this past issue and ensure they are on the absolute latest version of the plugin if an update has been released to address it. The plugin's strengths lie in its secure coding practices for SQL and output, but the historical vulnerability trend warrants caution.

Key Concerns

  • Unpatched CVE exists
  • Past XSS vulnerability in history
  • No nonce checks found
Vulnerabilities
1

فرم ساز فرم افزار Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22524medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

formafzar <= 2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 7, 2025 Patched in 2.1 (8d)
Code Analysis
Analyzed Mar 16, 2026

فرم ساز فرم افزار Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Attack Surface

فرم ساز فرم افزار Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[FormAfzar] formafzar.php:69
WordPress Hooks 4
filtermce_external_pluginsformafzar.php:78
filtermce_buttonsformafzar.php:79
actionadmin_headformafzar.php:83
actionenqueue_block_editor_assetsformafzar.php:117
Maintenance & Trust

فرم ساز فرم افزار Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJan 11, 2025
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs600
Developer Profile

فرم ساز فرم افزار Developer Profile

formafzar

1 plugin · 600 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect فرم ساز فرم افزار

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/formafzar/formafzar-block.js
Script Paths
https://formafzar.ir/pages/formbuilder/ravesh-formbuilder.js

HTML / DOM Fingerprints

HTML Comments
START---- FORMAFZAR FORM BUILDER ---- formafzar.ir ----->END--- FORMAFZAR FORM BUILDER ---- formafzar.ir ----->
Data Attributes
form-urlform-styleform-link-textform-themeform-button-colorform-button-icon
JS Globals
RaveshFormPathRaveshFormLangRaveshFormIsCRMRaveshFormIsFormican
Shortcode Output
<script type="text/javascript" src="https://formafzar.ir/pages/formbuilder/ravesh-formbuilder.js"<a href="" target="_blank"
FAQ

Frequently Asked Questions about فرم ساز فرم افزار