
Formative Security & Risk Analysis
wordpress.org/plugins/formativePowerful form builder with multi-step, conditional logic, styling, and 12+ integrations. Drag-and-drop interface for professional forms.
Is Formative Safe to Use in 2026?
Generally Safe
Score 100/100Formative has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "formative" v1.1.0 plugin exhibits a strong security posture based on the provided static analysis. The plugin demonstrates excellent practices, particularly in its use of prepared statements for SQL queries and its high percentage of properly escaped output. The absence of dangerous functions, external HTTP requests, and critical or high-severity taint flows is highly encouraging. Furthermore, the plugin implements nonce and capability checks appropriately on its entry points, minimizing the risk of unauthorized actions.
Key Concerns
- No critical or high severity taint flows found.
- No raw SQL queries found.
- High percentage of output properly escaped.
- Nonce checks present on entry points.
- Capability checks present on entry points.
- No known CVEs in vulnerability history.
- No bundled libraries.
- File operations present, but not analyzed for risk.
- Limited attack surface with all entry points protected.
Formative Security Vulnerabilities
Formative Code Analysis
Output Escaping
Data Flow Analysis
Formative Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
Formative Maintenance & Trust
Maintenance Signals
Community Trust
Formative Alternatives
Kreebi Forms
kreebi-forms
Kreebi Forms makes it simple to build flexible forms using Drag and Drop as well as JSON definition from the WordPress admin.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
Ninja Forms – The Contact Form Builder That Grows With You
ninja-forms
The 100% beginner friendly WordPress form builder. Drag & drop form fields to build beautiful, professional contact forms in minutes.
SureForms – Contact Form, Payment Form & Other Custom Form Builder
sureforms
The most beginner-friendly, AI Form Builder for WordPress to create contact forms, payment forms & other custom forms with advanced features, with …
Formative Developer Profile
1 plugin · 0 total installs
How We Detect Formative
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formative/build/admin.css/wp-content/plugins/formative/build/admin.js/wp-content/plugins/formative/build/frontend.css/wp-content/plugins/formative/build/frontend.js/wp-content/plugins/formative/build/admin.js/wp-content/plugins/formative/build/frontend.jsformative/build/admin.css?ver=formative/build/admin.js?ver=formative/build/frontend.css?ver=formative/build/frontend.js?ver=HTML / DOM Fingerprints
formative-rating-notice<!-- Only show on Formative admin pages. --><!-- Check if notice was dismissed. --><!-- Check if enough time has passed (7 days after activation). --><!-- Check if user has created at least 1 form. -->+1 moreformative_rating_dismiss=1formative_rating_dismiss=permanentformative_rating_dismiss=1formative_rating_dismiss=permanentajaxurlformative_dismiss_ratingformative_dismiss_rating