
Formito — Chatbot and Chat-style Form Builder Security & Risk Analysis
wordpress.org/plugins/formitoShortcode, oEmbed, and configurations for Formito.
Is Formito — Chatbot and Chat-style Form Builder Safe to Use in 2026?
Generally Safe
Score 85/100Formito — Chatbot and Chat-style Form Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Formito plugin v1.1.0 exhibits a generally strong security posture, with several positive indicators. The absence of known CVEs and a clean vulnerability history suggest a history of stable and secure development. Static analysis reveals good practices such as 100% prepared SQL statements and the presence of nonce and capability checks, indicating an effort to protect against common attack vectors. File operations and external HTTP requests are also absent, which reduces the potential for file manipulation or remote code execution vulnerabilities.
However, there are minor areas for improvement. While the attack surface is small, the plugin has one shortcode entry point which, combined with the relatively low 83% output escaping rate, presents a small risk of cross-site scripting (XSS) if user-supplied data is not consistently and properly sanitized before being displayed within this shortcode's output. The taint analysis also shows zero flows, which is positive, but it's important to ensure this remains the case as the plugin evolves and its attack surface potentially expands.
In conclusion, Formito v1.1.0 appears to be a secure plugin with robust coding practices in place. The low output escaping rate is the most significant, albeit minor, concern. The lack of past vulnerabilities is a strong positive sign. Continued vigilance in maintaining code quality and thorough testing will be crucial as the plugin is updated.
Key Concerns
- Lower output escaping rate (83%)
Formito — Chatbot and Chat-style Form Builder Security Vulnerabilities
Formito — Chatbot and Chat-style Form Builder Release Timeline
Formito — Chatbot and Chat-style Form Builder Code Analysis
Output Escaping
Formito — Chatbot and Chat-style Form Builder Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Formito — Chatbot and Chat-style Form Builder Maintenance & Trust
Maintenance Signals
Community Trust
Formito — Chatbot and Chat-style Form Builder Alternatives
Chatbot for WordPress by Collect.chat ⚡️
collectchat
Chatbots without AI are the easiest way to collect leads & data from visitors. Create a free chatbot without coding using Collect.chat.
Free AI Lead Generation Chatbot – ChatSale
ai-lead-form-builder-chatsale
ChatSale is a ChatGPT chatbot for a website that turns website visitors into qualified leads and booked appointments through smart conversations.
fobi chatbot
fobi-chatbot
A plugin that allows you to easily create and include chatbots to your wordpress installation.
MicroChat – Live Chat, Chatbots
microchat
Chatbots are the most convenient approach to collect leads and information from website visitors. MicroChat.io allows you to make a free chatbot witho …
Live Chat by Formilla – Real-time Chat & Chatbots Plugin
formilla-live-chat
Live chat software with real-time visitor monitoring and chatbots! Live chat with your visitors for free or use a chatbot to automate self-help.
Formito — Chatbot and Chat-style Form Builder Developer Profile
1 plugin · 10 total installs
How We Detect Formito — Chatbot and Chat-style Form Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.