
Formit – The Ultimate drag and drop WordPress Form Builder Security & Risk Analysis
wordpress.org/plugins/formitEasily design a dynamic WordPress form Builder using Formit, the top drag-and-drop form builder for contact, and more.
Is Formit – The Ultimate drag and drop WordPress Form Builder Safe to Use in 2026?
Generally Safe
Score 92/100Formit – The Ultimate drag and drop WordPress Form Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The FormIt v2.1.4 plugin exhibits a generally strong security posture, with excellent practices observed in SQL query handling and output escaping, both of which are 100% compliant with best practices. The absence of known CVEs and a clean vulnerability history are positive indicators. However, there are notable areas for improvement, particularly concerning the plugin's attack surface. The presence of four AJAX handlers without authentication checks represents a significant risk, as these could potentially be exploited by unauthenticated users. Additionally, the taint analysis revealed two flows with unsanitized paths, which, while not classified as critical or high severity by the analysis, warrant further investigation as they indicate potential pathways for data manipulation or injection if not properly mitigated at the application level. The plugin also demonstrates a good number of nonce and capability checks, but the unprotected entry points are a concern that could be addressed by implementing these checks more consistently across all handlers.
Key Concerns
- AJAX handlers without auth checks
- Taint flows with unsanitized paths
Formit – The Ultimate drag and drop WordPress Form Builder Security Vulnerabilities
Formit – The Ultimate drag and drop WordPress Form Builder Release Timeline
Formit – The Ultimate drag and drop WordPress Form Builder Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Formit – The Ultimate drag and drop WordPress Form Builder Attack Surface
AJAX Handlers 19
Shortcodes 1
WordPress Hooks 40
Maintenance & Trust
Formit – The Ultimate drag and drop WordPress Form Builder Maintenance & Trust
Maintenance Signals
Community Trust
Formit – The Ultimate drag and drop WordPress Form Builder Alternatives
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Contact Form by Supsystic
contact-form-by-supsystic
Contact Form Builder with drag-and-drop editor to create responsive, mobile ready contact forms in a second. Custom fields and contact form templates
Contact Form Query
contact-form-query
Add a contact form and receive new message notifications directly to your WordPress admin and to your email. Search and filter messages.
Contact Form Generator : Creative form builder for WordPress
contact-form-generator
Contact Form Generator is a creative and powerful contact form builder! You will get ready-to-use forms in 5 minutes!
Form Builder CP
cp-easy-form-builder
Form Builder CP is a contact form plugin for creating contact forms with a visual form builder and email them.
Formit – The Ultimate drag and drop WordPress Form Builder Developer Profile
1 plugin · 0 total installs
How We Detect Formit – The Ultimate drag and drop WordPress Form Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formit/assets/admin/js/form-builder.min.js/wp-content/plugins/formit/assets/admin/js/form-render.min.js/wp-content/plugins/formit/assets/admin/js/formit-admin-scripts.js/wp-content/plugins/formit/assets/admin/css/formit-admin-style.css/wp-content/plugins/formit/assets/admin/css/formit_form-builder-css.css/wp-content/plugins/formit/assets/admin/js/form-builder.min.js/wp-content/plugins/formit/assets/admin/js/form-render.min.js/wp-content/plugins/formit/assets/admin/js/formit-admin-scripts.jsformit/assets/admin/js/form-builder.min.js?ver=formit/assets/admin/js/form-render.min.js?ver=formit/assets/admin/js/formit-admin-scripts.js?ver=HTML / DOM Fingerprints
formit-form-builder<!-- Script Data -->formit_scripts_localizeformit_ajax_localize