
Formataway Security & Risk Analysis
wordpress.org/plugins/formatawayFormataway lets you exclude selected post formats from your post index page's main query.
Is Formataway Safe to Use in 2026?
Generally Safe
Score 85/100Formataway has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "formataway" v1.1.4 exhibits a generally strong security posture based on the provided static analysis. The complete absence of known vulnerabilities and CVEs in its history is a significant positive indicator, suggesting a history of secure development and maintenance. The static analysis further supports this with no identified critical or high-severity taint flows, dangerous functions, or SQL injection risks. All SQL queries appear to be properly prepared, and there are no file operations or external HTTP requests, which limits potential attack vectors.
However, there are a few areas that introduce minor concerns. The lack of any identified nonce checks or capability checks across all identified entry points is a notable weakness. While the current attack surface is reported as zero (meaning no exposed AJAX, REST API, or shortcodes are detected in this scan), this absence of checks means that if any entry points were to be introduced or missed in this analysis, they would be unprotected. Additionally, the output escaping is not fully comprehensive, with 40% of outputs not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without proper sanitization.
In conclusion, "formataway" v1.1.4 is likely a secure plugin for its current functionality, largely due to its clean vulnerability history and the absence of critical code-level risks. The primary areas for improvement would be to implement robust nonce and capability checks for any existing or future entry points and to ensure all output is properly escaped to mitigate potential XSS risks.
Key Concerns
- Outputs not properly escaped
- No nonce checks identified
- No capability checks identified
Formataway Security Vulnerabilities
Formataway Release Timeline
Formataway Code Analysis
Output Escaping
Formataway Attack Surface
WordPress Hooks 4
Maintenance & Trust
Formataway Maintenance & Trust
Maintenance Signals
Community Trust
Formataway Alternatives
Disable Admin Notices – Hide Dashboard Notifications
disable-admin-notices
Disable admin notices and hide dashboard notifications from plugins, themes and core. Hide all notices, selected ones, or show them in a single line.
Email Encoder – Protect Email Addresses and Phone Numbers
email-encoder-bundle
Protect email addresses and phone numbers on your site and hide them from spambots. Easy to use & flexible.
WP Ghost (Hide My WP Ghost) – Security & Firewall
hide-my-wp
Hide and Secure WP paths with the complete WP security suite for Site Hardening. Includes 8G Firewall, Brute Force protection, and Passkeys.
Title Remover
title-remover
Gives you the ability to hide the title of any post, page or custom post type item without affecting menus or titles in the admin area.
Dynamic Visibility for Elementor
dynamic-visibility-for-elementor
Show or hide Elementor widgets, containers, columns, and pages based on user role, date, device, and many other powerful conditions.
Formataway Developer Profile
2 plugins · 10 total installs
How We Detect Formataway
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
formataway/assets/css/formataway-admin.css?ver=formataway/assets/js/formataway-admin.js?ver=formataway/assets/css/formataway.css?ver=formataway/assets/js/formataway.js?ver=