FormFacade – Embed Google Forms in your website Security & Risk Analysis

wordpress.org/plugins/formfacade

Embed Google Forms™ in your wordpress site

1K active installs v1.4.1 PHP + WP 4.0+ Updated Apr 15, 2025
contact-formform-buildergoogle-formslead-formpayment-form
72
B · Generally Safe
CVEs total5
Unpatched1
Last CVEDec 31, 2025
Safety Verdict

Is FormFacade – Embed Google Forms in your website Safe to Use in 2026?

Mostly Safe

Score 72/100

FormFacade – Embed Google Forms in your website is generally safe to use. 5 past CVEs were resolved. Keep it updated.

5 known CVEs 1 unpatched Last CVE: Dec 31, 2025Updated 11mo ago
Risk Assessment

The static analysis of Formfacade v1.4.1 reveals a generally strong security posture, with excellent adherence to secure coding practices. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% proper output escaping are significant strengths. Furthermore, the plugin demonstrates no file operations or external HTTP requests, minimizing common attack vectors. The limited attack surface, with only one shortcode and no unprotected entry points, is also a positive indicator. However, the lack of nonce and capability checks on the identified shortcode is a notable concern. The vulnerability history presents a significant red flag, with five known CVEs, one of which remains unpatched. The prevalence of Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) vulnerabilities in the past suggests potential weaknesses in input sanitization or state management that could be exploited. While the current code analysis doesn't directly expose these, the historical pattern warrants caution and suggests that the identified shortcode might be susceptible if not handled with strict input validation and authorization checks.

In conclusion, Formfacade v1.4.1 exhibits commendable secure coding practices in its static analysis. The absence of critical code-level risks like raw SQL queries or unsanitized taint flows is reassuring. Nevertheless, the presence of an unpatched vulnerability and a history of CSRF and XSS issues, coupled with the lack of security checks on its single shortcode, introduces a tangible risk. Users should be aware of the potential for exploitation, especially given the historical patterns. The plugin's strengths lie in its clean code and modern security implementations, but these are undermined by its vulnerability track record and specific code gaps.

Key Concerns

  • Unpatched CVE found
  • Shortcode without nonce/capability checks
Vulnerabilities
5

FormFacade – Embed Google Forms in your website Security Vulnerabilities

CVEs by Year

4 CVEs in 2024
2024
1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
5

5 total CVEs

CVE-2025-62133medium · 4.3Cross-Site Request Forgery (CSRF)

FormFacade <= 1.4.1 - Cross-Site Request Forgery

Dec 31, 2025Unpatched
CVE-2024-54301medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

FormFacade <= 1.3.6 - Reflected Cross-Site Scripting

Dec 11, 2024 Patched in 1.3.7 (9d)
CVE-2024-9613medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

FormFacade – WordPress plugin for Google Forms <= 1.3.6 - Reflected Cross-Site Scripting

Oct 25, 2024 Patched in 1.3.7 (17d)
CVE-2024-43313medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

FormFacade <= 1.3.2 - Reflected Cross-Site Scripting

Aug 16, 2024 Patched in 1.3.3 (7d)
CVE-2024-25934medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

FormFacade <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode

Feb 20, 2024 Patched in 1.2.2 (24d)
Code Analysis
Analyzed Mar 16, 2026

FormFacade – Embed Google Forms in your website Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
39 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped39 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
formfacade_dashboard_page (formfacade.php:91)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

FormFacade – Embed Google Forms in your website Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[formfacade] formfacade.php:349
WordPress Hooks 2
actionadmin_menuformfacade.php:39
actionadmin_initformfacade.php:142
Maintenance & Trust

FormFacade – Embed Google Forms in your website Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedApr 15, 2025
PHP min version
Downloads25K

Community Trust

Rating100/100
Number of ratings4
Active installs1K
Developer Profile

FormFacade – Embed Google Forms in your website Developer Profile

manidoraisamy

3 plugins · 1K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect FormFacade – Embed Google Forms in your website

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/formfacade/assets/css/bootstrap.min.css/wp-content/plugins/formfacade/assets/css/style.css/wp-content/plugins/formfacade/assets/js/home.js/wp-content/plugins/formfacade/assets/js/lottie.js
Script Paths
/wp-content/plugins/formfacade/assets/js/home.js/wp-content/plugins/formfacade/assets/js/lottie.js
Version Parameters
formfacade_styles_bootstrapformfacade_styles_customformfacade_home_scriptlottie_script

HTML / DOM Fingerprints

Data Attributes
id="myIframe"
FAQ

Frequently Asked Questions about FormFacade – Embed Google Forms in your website