Formito — Chatbot and Chat-style Form Builder Security & Risk Analysis

wordpress.org/plugins/formito

Shortcode, oEmbed, and configurations for Formito.

10 active installs v1.1.0 PHP 5.2.4+ WP 4.6+ Updated Oct 14, 2020
chatchat-botchatbotformlead-generation
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Formito — Chatbot and Chat-style Form Builder Safe to Use in 2026?

Generally Safe

Score 85/100

Formito — Chatbot and Chat-style Form Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The Formito plugin v1.1.0 exhibits a generally strong security posture, with several positive indicators. The absence of known CVEs and a clean vulnerability history suggest a history of stable and secure development. Static analysis reveals good practices such as 100% prepared SQL statements and the presence of nonce and capability checks, indicating an effort to protect against common attack vectors. File operations and external HTTP requests are also absent, which reduces the potential for file manipulation or remote code execution vulnerabilities.

However, there are minor areas for improvement. While the attack surface is small, the plugin has one shortcode entry point which, combined with the relatively low 83% output escaping rate, presents a small risk of cross-site scripting (XSS) if user-supplied data is not consistently and properly sanitized before being displayed within this shortcode's output. The taint analysis also shows zero flows, which is positive, but it's important to ensure this remains the case as the plugin evolves and its attack surface potentially expands.

In conclusion, Formito v1.1.0 appears to be a secure plugin with robust coding practices in place. The low output escaping rate is the most significant, albeit minor, concern. The lack of past vulnerabilities is a strong positive sign. Continued vigilance in maintaining code quality and thorough testing will be crucial as the plugin is updated.

Key Concerns

  • Lower output escaping rate (83%)
Vulnerabilities
None known

Formito — Chatbot and Chat-style Form Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Formito — Chatbot and Chat-style Form Builder Release Timeline

v1.0.0
Code Analysis
Analyzed Mar 17, 2026

Formito — Chatbot and Chat-style Form Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
15 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped18 total outputs
Attack Surface

Formito — Chatbot and Chat-style Form Builder Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[formito] formito.php:44
WordPress Hooks 6
actioninitformito.php:25
actionadmin_initformito.php:26
actionadmin_menuformito.php:27
actionwp_footerformito.php:29
actionplugins_loadedformito.php:30
actionactivated_pluginformito.php:37
Maintenance & Trust

Formito — Chatbot and Chat-style Form Builder Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedOct 14, 2020
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Formito — Chatbot and Chat-style Form Builder Developer Profile

Formito

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Formito — Chatbot and Chat-style Form Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Formito — Chatbot and Chat-style Form Builder