Forminator Add-on : User Info Security & Risk Analysis

wordpress.org/plugins/forminator-add-on-user-info

Forminator Add-on : User Info enhancements.

100 active installs v1.0.0 PHP 7.4+ WP 6.4+ Updated Nov 19, 2024
forminatorforminator-add-onsubmissionsuser-info
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Forminator Add-on : User Info Safe to Use in 2026?

Generally Safe

Score 92/100

Forminator Add-on : User Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the plugin 'forminator-add-on-user-info' v1.0.0 exhibits a strong security posture with no immediately apparent vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate no use of dangerous functions, all SQL queries utilize prepared statements, output is properly escaped, and there are no file operations or external HTTP requests. The lack of any recorded vulnerabilities, historical or current, further reinforces this positive assessment. However, the data also shows a complete absence of nonce checks and capability checks. While the current lack of exposed entry points means this is not an immediate risk, it represents a potential weakness if the plugin were to evolve or interact with other components in the future, making it less robust against potential future attack vectors. Overall, the plugin appears secure for its current functionality, adhering to good coding practices where implemented, but has inherent limitations in its security framework due to the lack of authentication and authorization checks on potential future entry points.

Key Concerns

  • No capability checks found
  • No nonce checks found
Vulnerabilities
None known

Forminator Add-on : User Info Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Forminator Add-on : User Info Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Forminator Add-on : User Info Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionforminator_custom_form_submit_before_set_fieldsinc\hooks__forminator.php:53
actionforminator_fields_mappersinc\hooks__forminator.php:75
actionforminator_query_entries_whereinc\hooks__forminator.php:89
Maintenance & Trust

Forminator Add-on : User Info Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedNov 19, 2024
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Forminator Add-on : User Info Developer Profile

Web Dev Gandalf

1 plugin · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Forminator Add-on : User Info

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
[view-only-own-submissions for non-admin users]
FAQ

Frequently Asked Questions about Forminator Add-on : User Info