
Formentor – Elementor Form Plus Security & Risk Analysis
wordpress.org/plugins/formentor-elementor-form-plusSend forms directly to Google Sheets, an elementor plugin
Is Formentor – Elementor Form Plus Safe to Use in 2026?
Generally Safe
Score 85/100Formentor – Elementor Form Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "formentor-elementor-form-plus" v1 plugin exhibits a concerning security posture, primarily due to a significant attack surface with no authentication checks on its AJAX handlers. While the plugin demonstrates good practices in SQL query handling and avoids dangerous functions and file operations, the lack of authorization on its entry points is a major weakness. The static analysis reveals 4 AJAX handlers, all of which lack authentication, presenting a direct pathway for unauthorized actions if vulnerabilities exist within them. Taint analysis, while not revealing critical or high severity issues, did identify flows with unsanitized paths, which, when combined with unprotected entry points, could potentially lead to exploitation. The plugin's vulnerability history is clean, with no recorded CVEs. This absence of historical vulnerabilities could indicate diligent development or simply a lack of past discovery. However, the current code analysis strongly suggests that the unprotected AJAX endpoints are the most significant risk, potentially allowing attackers to trigger plugin functionality without proper authorization.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint flows
- Low output escaping coverage
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
Formentor – Elementor Form Plus Security Vulnerabilities
Formentor – Elementor Form Plus Code Analysis
Output Escaping
Data Flow Analysis
Formentor – Elementor Form Plus Attack Surface
AJAX Handlers 4
WordPress Hooks 14
Maintenance & Trust
Formentor – Elementor Form Plus Maintenance & Trust
Maintenance Signals
Community Trust
Formentor – Elementor Form Plus Alternatives
EntryDashboard – Database Addon & Sync for WPForms, CF7, Elementor & More
entries-manager
Saves, manages, and sync all form submissions to your WordPress database. The most powerful Database Addon for WPForms, Contact Form 7, and Elementor …
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
GSheetConnector for CF7 – Connect Contact Form 7 to Google Sheets and Send Form Submissions in Real Time
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
Styler Mate for Contact Form 7
cf7-styler-for-divi
Style and enhance Contact Form 7 for Divi, Bricks, Elementor, Gutenberg, and more.
Void Contact Form 7 Widget For Elementor Page Builder
cf7-widget-elementor
This WordPress Plugin Adds Contact Form 7 widget element to Elementor page builder for easy drag & drop the created contact forms with CF7 (contac …
Formentor – Elementor Form Plus Developer Profile
3 plugins · 240 total installs
How We Detect Formentor – Elementor Form Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formentor-elementor-form-plus/addtrackingform.css/wp-content/plugins/formentor-elementor-form-plus/adminscript.js/wp-content/plugins/formentor-elementor-form-plus/adminscript.js/wp-content/plugins/formentor-elementor-form-plus/addtrackingform.css?ver=/wp-content/plugins/formentor-elementor-form-plus/adminscript.js?ver=HTML / DOM Fingerprints
form_one_by_oneform_mobiledata-progres_bardata-send_icondata-trackingdata-actiondata-categorydata-fbclient_to_google_sheet/wp-json/client_to_google_sheet/v1/askAccsesToken/wp-json/client_to_google_sheet/v1/savetokeb