
FormFacade – Embed Google Forms in your website Security & Risk Analysis
wordpress.org/plugins/formfacadeEmbed Google Forms™ in your wordpress site
Is FormFacade – Embed Google Forms in your website Safe to Use in 2026?
Mostly Safe
Score 72/100FormFacade – Embed Google Forms in your website is generally safe to use. 5 past CVEs were resolved. Keep it updated.
The static analysis of Formfacade v1.4.1 reveals a generally strong security posture, with excellent adherence to secure coding practices. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% proper output escaping are significant strengths. Furthermore, the plugin demonstrates no file operations or external HTTP requests, minimizing common attack vectors. The limited attack surface, with only one shortcode and no unprotected entry points, is also a positive indicator. However, the lack of nonce and capability checks on the identified shortcode is a notable concern. The vulnerability history presents a significant red flag, with five known CVEs, one of which remains unpatched. The prevalence of Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) vulnerabilities in the past suggests potential weaknesses in input sanitization or state management that could be exploited. While the current code analysis doesn't directly expose these, the historical pattern warrants caution and suggests that the identified shortcode might be susceptible if not handled with strict input validation and authorization checks.
In conclusion, Formfacade v1.4.1 exhibits commendable secure coding practices in its static analysis. The absence of critical code-level risks like raw SQL queries or unsanitized taint flows is reassuring. Nevertheless, the presence of an unpatched vulnerability and a history of CSRF and XSS issues, coupled with the lack of security checks on its single shortcode, introduces a tangible risk. Users should be aware of the potential for exploitation, especially given the historical patterns. The plugin's strengths lie in its clean code and modern security implementations, but these are undermined by its vulnerability track record and specific code gaps.
Key Concerns
- Unpatched CVE found
- Shortcode without nonce/capability checks
FormFacade – Embed Google Forms in your website Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
FormFacade <= 1.4.1 - Cross-Site Request Forgery
FormFacade <= 1.3.6 - Reflected Cross-Site Scripting
FormFacade – WordPress plugin for Google Forms <= 1.3.6 - Reflected Cross-Site Scripting
FormFacade <= 1.3.2 - Reflected Cross-Site Scripting
FormFacade <= 1.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
FormFacade – Embed Google Forms in your website Code Analysis
Output Escaping
Data Flow Analysis
FormFacade – Embed Google Forms in your website Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
FormFacade – Embed Google Forms in your website Maintenance & Trust
Maintenance Signals
Community Trust
FormFacade – Embed Google Forms in your website Alternatives
Ninja Forms – The Contact Form Builder That Grows With You
ninja-forms
The 100% beginner friendly WordPress form builder. Drag & drop form fields to build beautiful, professional contact forms in minutes.
SureForms – Contact Form, Payment Form & Other Custom Form Builder
sureforms
The most beginner-friendly, AI Form Builder for WordPress to create contact forms, payment forms & other custom forms with advanced features, with …
Kali Forms — Contact Form & Drag-and-Drop Builder
kali-forms
Build contact forms for your WordPress website in minutes through the Drag & Drop builder and Guided Emails for entries notifications.
Lead Form Builder & Contact Form
lead-form-builder
Fast Drag & Drop Contact From Builder and Lead Generation Tool With Google One Tap Login. Supports Block Editor.
ApplyOnline – Application Form Builder and Manager
apply-online
Powerful & intuitive plugin to post ads and start receiving applications online.
FormFacade – Embed Google Forms in your website Developer Profile
3 plugins · 1K total installs
How We Detect FormFacade – Embed Google Forms in your website
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formfacade/assets/css/bootstrap.min.css/wp-content/plugins/formfacade/assets/css/style.css/wp-content/plugins/formfacade/assets/js/home.js/wp-content/plugins/formfacade/assets/js/lottie.js/wp-content/plugins/formfacade/assets/js/home.js/wp-content/plugins/formfacade/assets/js/lottie.jsformfacade_styles_bootstrapformfacade_styles_customformfacade_home_scriptlottie_scriptHTML / DOM Fingerprints
id="myIframe"