Formidable Anti-Spam Security & Risk Analysis

wordpress.org/plugins/formidable-anti-spam

A lightweight Formidable Pro anti-spam add-on that requires no interaction with the user.

70 active installs v1.0 PHP + WP 3.7+ Updated Oct 1, 2014
anti-spambotformidableformidable-prospam
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Formidable Anti-Spam Safe to Use in 2026?

Generally Safe

Score 85/100

Formidable Anti-Spam has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'formidable-anti-spam' plugin v1.0 currently exhibits a seemingly strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that could serve as entry points for malicious actors. Furthermore, the code signals do not indicate the presence of dangerous functions, raw SQL queries, file operations, external HTTP requests, or unexploited taint flows. The absence of any known vulnerabilities in its history also contributes to a positive initial assessment.

However, a significant concern arises from the complete lack of output escaping (0% properly escaped). This suggests that any output generated by the plugin could be vulnerable to Cross-Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts into web pages viewed by other users. The absence of nonces and capability checks across all potential entry points, though currently minimal, also poses a future risk if the plugin's attack surface were to expand or if new vulnerabilities were discovered in its logic. While the current lack of vulnerabilities is a strength, the critical flaw in output escaping overshadows the other positive indicators, demanding immediate attention.

Key Concerns

  • All output is unescaped
  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Formidable Anti-Spam Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Formidable Anti-Spam Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped8 total outputs
Attack Surface

Formidable Anti-Spam Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionfrm_entry_formclasses\FrmAntiSpamActions.php:7
filterfrm_validate_field_entryclasses\FrmAntiSpamActions.php:8
actionfrm_add_form_settings_sectionclasses\FrmAntiSpamFormOptions.php:7
filterfrm_setup_new_form_varsclasses\FrmAntiSpamFormOptions.php:8
filterfrm_setup_edit_form_varsclasses\FrmAntiSpamFormOptions.php:9
filterfrm_form_options_before_updateclasses\FrmAntiSpamFormOptions.php:10
actionfrm_add_settings_sectionclasses\FrmAntiSpamGlobalSettingsForm.php:7
Maintenance & Trust

Formidable Anti-Spam Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedOct 1, 2014
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs70
Developer Profile

Formidable Anti-Spam Developer Profile

thomstark

5 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Formidable Anti-Spam

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/formidable-anti-spam/css/style.css
Version Parameters
formidable-anti-spam/css/style.css?ver=formidable-anti-spam.php?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Formidable Anti-Spam