FormDesigner – online web form builder Security & Risk Analysis

wordpress.org/plugins/formdesigner

Multifunctional online constructor of web forms, surveys, quizzes and calculators for the website.

200 active installs v2.2.0 PHP + WP 4.5.0+ Updated Mar 29, 2022
form-builderform-generatorformdesignerquizquiz-builder
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FormDesigner – online web form builder Safe to Use in 2026?

Generally Safe

Score 85/100

FormDesigner – online web form builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The formdesigner plugin v2.2.0 exhibits a mixed security posture. On the positive side, the absence of any known CVEs and the use of prepared statements for all SQL queries are strong indicators of good development practices. The plugin also avoids bundling external libraries and making excessive external HTTP requests, which reduces potential attack vectors.

However, significant security concerns arise from the static analysis. The plugin has a relatively large attack surface with 4 total entry points, and a concerning 3 of these are completely unprotected by authentication checks. Furthermore, only 15% of its output is properly escaped, suggesting a high likelihood of cross-site scripting (XSS) vulnerabilities. The lack of nonce checks on AJAX handlers is another critical weakness, as it can allow unauthorized users to trigger plugin functionalities.

Given the lack of historical vulnerabilities, it might suggest that the plugin's existing protections have been sufficient up to this point. However, the current code analysis reveals several fundamental security oversights that expose the plugin and its users to significant risk, particularly from XSS and unauthorized action execution.

Key Concerns

  • 3 unprotected AJAX handlers
  • Low output escaping (15%)
  • No nonce checks on AJAX
  • 1 unprotected shortcode
Vulnerabilities
None known

FormDesigner – online web form builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

FormDesigner – online web form builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

15% escaped20 total outputs
Attack Surface
3 unprotected

FormDesigner – online web form builder Attack Surface

Entry Points4
Unprotected3

AJAX Handlers 3

authwp_ajax_formdesigner_popupclass.formdesigner.php:29
authwp_ajax_formdesigner_authclass.formdesigner.php:30
authwp_ajax_formdesigner_load_formsclass.formdesigner.php:31

Shortcodes 1

[formdesigner] class.formdesigner.php:38
WordPress Hooks 7
actioninitclass.formdesigner.php:21
actionplugins_loadedclass.formdesigner.php:23
actionadmin_menuclass.formdesigner.php:25
actionadmin_enqueue_scriptsclass.formdesigner.php:28
filtermce_external_pluginsclass.formdesigner.php:36
filtermce_buttonsclass.formdesigner.php:37
actioninitclass.formdesigner.php:39
Maintenance & Trust

FormDesigner – online web form builder Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMar 29, 2022
PHP min version
Downloads14K

Community Trust

Rating80/100
Number of ratings1
Active installs200
Developer Profile

FormDesigner – online web form builder Developer Profile

ishamshur

1 plugin · 200 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FormDesigner – online web form builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/formdesigner/src/gutenberg.js/wp-content/plugins/formdesigner/src/editor.css
Script Paths
/wp-content/plugins/formdesigner/src/gutenberg.js
Version Parameters
formdesigner/src/editor.css?ver=formdesigner/src/gutenberg.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-formdesigner-block
JS Globals
formdesigner_hostformdesigner_langs
Shortcode Output
formdesigner_shortcode
FAQ

Frequently Asked Questions about FormDesigner – online web form builder