
Formidable Kinetic Security & Risk Analysis
wordpress.org/plugins/formidable-kineticDynamically display any Formidable Form and form fields. One page. One shortcode. Infinite possibilities.
Is Formidable Kinetic Safe to Use in 2026?
Generally Safe
Score 85/100Formidable Kinetic has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "formidable-kinetic" plugin v1.1.01 exhibits a generally good security posture based on the provided static analysis. A notable strength is the complete absence of unprotected entry points, including AJAX handlers and REST API routes, indicating that all interactions require proper authentication. The lack of file operations and external HTTP requests further reduces the attack surface. The plugin also demonstrates good practices by including nonce and capability checks for its identified entry points. The vulnerability history being completely clear of any known CVEs is also a very positive sign, suggesting a mature and well-maintained codebase.
However, the analysis does reveal areas for improvement. The most significant concern is the use of SQL queries without prepared statements. This represents a substantial risk of SQL injection vulnerabilities, especially since 100% of the identified SQL queries fall into this category. Additionally, a very low percentage of output escaping (9%) is a significant weakness. This high rate of unescaped output opens the door to cross-site scripting (XSS) attacks, where malicious code could be injected into the user interface.
In conclusion, while the plugin benefits from robust authentication on its entry points and a clean vulnerability history, the critical flaws in SQL query preparation and output escaping are serious concerns that require immediate attention. Addressing these specific coding practices would significantly enhance the plugin's security.
Key Concerns
- 100% of SQL queries are not using prepared statements
- Only 9% of output is properly escaped
Formidable Kinetic Security Vulnerabilities
Formidable Kinetic Code Analysis
SQL Query Safety
Output Escaping
Formidable Kinetic Attack Surface
AJAX Handlers 1
Shortcodes 2
WordPress Hooks 8
Maintenance & Trust
Formidable Kinetic Maintenance & Trust
Maintenance Signals
Community Trust
Formidable Kinetic Alternatives
Formidable A/B Tests
formidable-ab-tests
Easily A/B test your Formidable Pro created forms.
Formidable Customizations
formidable-customizations
A compendium of useful customizations and extensions for Formidable Pro. Easily customize your form fields from one location.
WP Contact Slider – Contact Form Slider Widget
wp-contact-slider
Helps you to show slide out contact form to display CF7, Gravity forms, Ninja Forms, WP Forms, display random text/HTML and support some other forms.
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin
cf7-zoho
Send Contact Form 7, WPforms, Elementor, Formidable, Ninja Forms and many other contact form submissions to zoho CRM and Bigin.
Account Engagement
pardot
Integrate Account Engagement with WordPress: easily track visitors, embed forms and dynamic content in pages and posts, or use the forms or dynamic co …
Formidable Kinetic Developer Profile
5 plugins · 130 total installs
How We Detect Formidable Kinetic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formidable-kinetic/admin/css/kinetic.css/wp-content/plugins/formidable-kinetic/admin/js/kinetic.js/wp-content/plugins/formidable-kinetic/admin/js/kinetic-tinymce.jsadmin/js/kinetic.jsadmin/js/kinetic-tinymce.jsformidable-kinetic/admin/css/kinetic.css?ver=formidable-kinetic/admin/js/kinetic.js?ver=formidable-kinetic/admin/js/kinetic-tinymce.js?ver=HTML / DOM Fingerprints
<!-- SECURITY --><!-- DEFINITIONS --><!-- INCLUDES --><!-- SHORTCODES -->+9 moredata-mce-placeholderSSFK_VERSIONSSFK_FILESSFK_PATHSSFK_ADMINSSFK_ADMIN_INCLUDESSSFK_FOLDER+6 more<a href="" data-mce-href="" class="" target="