
Contact form builder for Gutenberg – Formello Security & Risk Analysis
wordpress.org/plugins/formelloLight-weight and easy plugin create forms inside the block editor.
Is Contact form builder for Gutenberg – Formello Safe to Use in 2026?
Generally Safe
Score 100/100Contact form builder for Gutenberg – Formello has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Formello v2.7.1 plugin exhibits a generally strong security posture, adhering to several best practices such as 100% output escaping and a high percentage of prepared SQL statements. The absence of known CVEs and a clean vulnerability history are positive indicators of the developer's commitment to security. However, the plugin does present some concerning security weaknesses that warrant attention. Specifically, the presence of two AJAX handlers without authentication checks creates a direct attack vector for unauthorized actions. Additionally, the taint analysis revealed two flows with unsanitized paths, which, while not flagged as critical or high severity in this analysis, represent a potential risk if these paths are reachable by unauthenticated users or if the data involved is sensitive. The limited file operations and external HTTP requests are also good points, but the two unprotected entry points and the potential for unsanitized path traversals are the primary areas of concern.
Key Concerns
- AJAX handlers without authentication checks
- Flows with unsanitized paths
Contact form builder for Gutenberg – Formello Security Vulnerabilities
Contact form builder for Gutenberg – Formello Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Contact form builder for Gutenberg – Formello Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 31
Scheduled Events 3
Maintenance & Trust
Contact form builder for Gutenberg – Formello Maintenance & Trust
Maintenance Signals
Community Trust
Contact form builder for Gutenberg – Formello Alternatives
Gutenberg Forms Add-on for MailPoet
guten-forms-mailpoet
MailPoet add-on for Gutenberg Forms. Connect with MailPoet and send leads/subscribers to your MailPoet list with the form submissions.
Nelio Forms
nelio-forms
An intuitive form builder based on open WordPress technologies
Gutenberg Forms Add-on for Akismet
guten-forms-akismet
Akismet add-on for Gutenberg Forms. Connect with Akismet and protect your form submissions against spam via their global database of spam.
RioForms – Drag & Drop Contact Form Builder
rioforms
Create stunning, responsive forms in minutes with the next-gen WordPress drag-and-drop contact form builder plugin.
SiteOrigin Widgets Bundle
so-widgets-bundle
Essential elements for modern websites. Add buttons, sliders, heroes, maps, images, carousels, features, icons, more. Create dynamic pages easily.
Contact form builder for Gutenberg – Formello Developer Profile
5 plugins · 13K total installs
How We Detect Contact form builder for Gutenberg – Formello
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formello/build/style-admin.css/wp-content/plugins/formello/build/admin.js/wp-content/plugins/formello/build/form-settings.js/wp-content/plugins/formello/build/admin.js/wp-content/plugins/formello/build/form-settings.jsformello/build/style-admin.css?ver=formello/build/admin.js?ver=formello/build/form-settings.js?ver=HTML / DOM Fingerprints
formello-admin-appdata-formello-form-iddata-formello-entries-urldata-formello-submit-urlformello/wp-json/formello/v1/settings/wp-json/formello/v1/new-form/wp-json/formello/v1/form-settings/wp-json/formello/v1/submit/wp-json/formello/v1/upload[formello_form