
FormFacade – Embed Google Forms in your website Security & Risk Analysis
wordpress.org/plugins/formfacadeEmbed Google Forms™ in your wordpress site
Is FormFacade – Embed Google Forms in your website Safe to Use in 2026?
Use With Caution
Score 64/100FormFacade – Embed Google Forms in your website has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The static analysis of Formfacade v1.4.1 reveals a generally strong security posture, with excellent adherence to secure coding practices. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% proper output escaping are significant strengths. Furthermore, the plugin demonstrates no file operations or external HTTP requests, minimizing common attack vectors. The limited attack surface, with only one shortcode and no unprotected entry points, is also a positive indicator. However, the lack of nonce and capability checks on the identified shortcode is a notable concern. The vulnerability history presents a significant red flag, with five known CVEs, one of which remains unpatched. The prevalence of Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) vulnerabilities in the past suggests potential weaknesses in input sanitization or state management that could be exploited. While the current code analysis doesn't directly expose these, the historical pattern warrants caution and suggests that the identified shortcode might be susceptible if not handled with strict input validation and authorization checks.
In conclusion, Formfacade v1.4.1 exhibits commendable secure coding practices in its static analysis. The absence of critical code-level risks like raw SQL queries or unsanitized taint flows is reassuring. Nevertheless, the presence of an unpatched vulnerability and a history of CSRF and XSS issues, coupled with the lack of security checks on its single shortcode, introduces a tangible risk. Users should be aware of the potential for exploitation, especially given the historical patterns. The plugin's strengths lie in its clean code and modern security implementations, but these are undermined by its vulnerability track record and specific code gaps.
Key Concerns
- Unpatched CVE found
- Shortcode without nonce/capability checks
FormFacade – Embed Google Forms in your website Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
FormFacade <= 1.4.1 - Cross-Site Request Forgery
FormFacade <= 1.3.6 - Reflected Cross-Site Scripting
FormFacade – WordPress plugin for Google Forms <= 1.3.6 - Reflected Cross-Site Scripting
FormFacade <= 1.3.2 - Reflected Cross-Site Scripting
FormFacade <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
FormFacade – Embed Google Forms in your website Release Timeline
FormFacade – Embed Google Forms in your website Code Analysis
Output Escaping
Data Flow Analysis
FormFacade – Embed Google Forms in your website Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
FormFacade – Embed Google Forms in your website Maintenance & Trust
Maintenance Signals
Community Trust
FormFacade – Embed Google Forms in your website Alternatives
Ninja Forms – The Contact Form Builder That Grows With You
ninja-forms
The 100% beginner friendly WordPress form builder. Drag & drop form fields to build beautiful, professional contact forms in minutes.
SureForms – Contact Form, Payment Form & Other Custom Form Builder
sureforms
The most beginner-friendly AI Form Builder for WordPress. Create contact, payment, quiz & custom forms with advanced features in minutes.
Kali Forms — Contact Form & Drag-and-Drop Builder
kali-forms
Build contact forms for your WordPress website in minutes through the Drag & Drop builder and Guided Emails for entries notifications.
Lead Form Builder & Contact Form
lead-form-builder
Drag & Drop Contact Form Builder for WordPress to create contact, lead generation, newsletter & registration forms. Works with Elementor & Gutenberg.
ApplyOnline – Application Form Builder and Manager
apply-online
Powerful & intuitive plugin to post ads and start receiving applications online.
FormFacade – Embed Google Forms in your website Developer Profile
3 plugins · 1K total installs
How We Detect FormFacade – Embed Google Forms in your website
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formfacade/assets/css/bootstrap.min.css/wp-content/plugins/formfacade/assets/css/style.css/wp-content/plugins/formfacade/assets/js/home.js/wp-content/plugins/formfacade/assets/js/lottie.js/wp-content/plugins/formfacade/assets/js/home.js/wp-content/plugins/formfacade/assets/js/lottie.jsformfacade_styles_bootstrapformfacade_styles_customformfacade_home_scriptlottie_scriptHTML / DOM Fingerprints
id="myIframe"