
FormCraft – Form Builder Security & Risk Analysis
wordpress.org/plugins/formcraft-form-builderCreate gorgeous forms for your site using this drag-and-drop form builder.
Is FormCraft – Form Builder Safe to Use in 2026?
Mostly Safe
Score 79/100FormCraft – Form Builder is generally safe to use though it hasn't been updated recently. 10 past CVEs were resolved. Keep it updated.
The "formcraft-form-builder" plugin version 1.2.11 exhibits a mixed security posture. On the positive side, the static analysis reveals a robust use of prepared statements for all SQL queries and a high percentage of properly escaped outputs. Furthermore, all identified AJAX and REST API entry points have checks in place, indicating good practices in handling user interactions and preventing direct unauthenticated access. The absence of external HTTP requests and bundled libraries further reduces potential attack vectors.
However, several concerns warrant attention. The taint analysis indicates three flows with unsanitized paths, specifically marked as high severity. While these are not currently marked as critical, unsanitized paths can be a precursor to vulnerabilities if not addressed. Compounding this, the plugin has a significant history of known vulnerabilities, with 10 CVEs recorded, including 2 critical and 2 high severity issues in the past. Although none are currently unpatched, this history of diverse and severe vulnerability types (including Missing Authorization, XSS, SSRF, CSRF, and SQL Injection) suggests a pattern of insecure coding practices in previous versions. This indicates a potential for new vulnerabilities to emerge in future updates if diligent security practices are not maintained.
In conclusion, while version 1.2.11 demonstrates improvements in specific areas like SQL querying and output escaping, the presence of high-severity unsanitized paths and the plugin's extensive history of critical and high-severity vulnerabilities necessitate a cautious approach. The risk is moderate, primarily driven by the potential for undiscovered vulnerabilities stemming from past patterns and the identified taint flows.
Key Concerns
- High severity taint flows (unsanitized paths)
- Significant history of critical CVEs
- Significant history of high CVEs
- 71% of outputs properly escaped
FormCraft – Form Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
FormCraft <= 1.2.10 - Missing Authorization
FormCraft <= 1.2.7 - Missing Authorization via formcraft_nag_update
FormCraft <= 1.2.6 - Authenticated (Admin+) Stored Cross-Site Scripting
FormCraft Premium <= 3.9.6 - Authenticated(Administrator+) SQL Injection
FormCraft <= 1.2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via fcb shortcode
FormCraft Basic <= 1.2.5 - Authenticated (Admin+) Stored Cross-Site Scripting
Formcraft3 <= 3.8.27 - Server Side Request Forgery
FormCraft <= 1.2.1 - Cross-Site Request Forgery
FormCraft <= 1.2.1 - Cross-Site Request Forgery
FormCraft Basic 1.0.5 - SQL Injection via id Parameter
FormCraft – Form Builder Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FormCraft – Form Builder Attack Surface
AJAX Handlers 10
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
FormCraft – Form Builder Maintenance & Trust
Maintenance Signals
Community Trust
FormCraft – Form Builder Alternatives
MailPoet Add-On for FormCraft
mailpoet-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your MailPoet list.
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
metform
The most popular Elementor forms builder to create WordPress forms like contact forms, booking forms, feedback form, survey forms, application forms a …
Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder
formidable
The most advanced WordPress forms plugin. Go beyond contact forms with our drag and drop form builder for surveys, quizzes, and more.
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder
everest-forms
The best WordPress form builder. Create contact forms, payment forms, conversational forms, custom forms, surveys, & quizzes using drag and drop.
Ultra Addons for Contact Form 7
ultimate-addons-for-contact-form-7
50+ Essential Addons for Contact Form 7 - Conditional Fields, Multi Step, Redirection, Columns, WooCommerce, Mailchimp & more
FormCraft – Form Builder Developer Profile
8 plugins · 11K total installs
How We Detect FormCraft – Form Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formcraft-form-builder/assets/formcraft-icon.css/wp-content/plugins/formcraft-form-builder/assets/css/form.main.css/wp-content/plugins/formcraft-form-builder/assets/css/common-elements.css/wp-content/plugins/formcraft-form-builder/assets/images/plus.png/wp-content/plugins/formcraft-form-builder/assets/css/fcbmodal.css/wp-content/plugins/formcraft-form-builder/assets/js/fcbmodal.js/wp-content/plugins/formcraft-form-builder/assets/js/add-form-button.js/wp-content/plugins/formcraft-form-builder/assets/css/add-form-button.css/wp-content/plugins/formcraft-form-builder/assets/js/fcbmodal.js/wp-content/plugins/formcraft-form-builder/assets/js/add-form-button.jsformcraft-form-builder/assets/formcraft-icon.css?ver=formcraft-form-builder/assets/css/form.main.css?ver=formcraft-form-builder/assets/css/common-elements.css?ver=formcraft-form-builder/assets/css/fcbmodal.css?ver=formcraft-form-builder/assets/js/fcbmodal.js?ver=formcraft-form-builder/assets/js/add-form-button.js?ver=formcraft-form-builder/assets/css/add-form-button.css?ver=HTML / DOM Fingerprints
formcraftbasic-cssfcb_afbfcbmodaldata-targetdata-toggle