
Forms: 3rd-Party Inject Results Security & Risk Analysis
wordpress.org/plugins/forms-3rd-party-inject-resultsInjects the response from a Forms: 3rdparty submission into the original contact form.
Is Forms: 3rd-Party Inject Results Safe to Use in 2026?
Generally Safe
Score 85/100Forms: 3rd-Party Inject Results has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "forms-3rd-party-inject-results" v0.3 plugin exhibits a surprisingly robust security posture based on the provided static analysis. The absence of any identified attack surface points like AJAX handlers, REST API routes, or shortcodes is a significant strength. Furthermore, the lack of dangerous functions, file operations, external HTTP requests, and the consistent use of prepared statements for SQL queries indicate a deliberate effort towards secure coding practices. The vulnerability history being completely clean also suggests a well-maintained and secure codebase over time.
However, a notable concern arises from the low percentage (22%) of properly escaped outputs. This indicates that a significant portion of user-supplied data that is displayed to the user is not being properly sanitized, creating a potential for Cross-Site Scripting (XSS) vulnerabilities. While no taint flows were identified, this could be due to the limited scope of the analysis or the specific nature of how data is handled. The absence of nonce checks and capability checks, especially if there were any hidden entry points not detected, could also pose a risk if the plugin were to evolve and introduce such features without adequate security measures.
Key Concerns
- Low output escaping rate
Forms: 3rd-Party Inject Results Security Vulnerabilities
Forms: 3rd-Party Inject Results Code Analysis
Output Escaping
Forms: 3rd-Party Inject Results Attack Surface
WordPress Hooks 1
Maintenance & Trust
Forms: 3rd-Party Inject Results Maintenance & Trust
Maintenance Signals
Community Trust
Forms: 3rd-Party Inject Results Alternatives
AFI – The Easiest Integration Plugin
advanced-form-integration
Connect any WordPress form or event to 200+ apps — no code. Send leads, orders, and signups to your CRM, email, or sheets in minutes.
Lenix Leads Collector
lenix-elementor-leads-addon
Leads Collector, Collects forms entries from Elementor,Cf7,WPForms and more with export to CSV.
Contact Form to Any API
contact-form-to-any-api
Send Contact Form 7 submissions to any API, Webhook or CRM - quick setup, flexible payloads, endpoints and authentication.
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin
cf7-zoho
Send Contact Form 7, WPforms, Elementor, Formidable, Ninja Forms and many other contact form submissions to zoho CRM and Bigin.
Zoho CRM Lead Magnet
zoho-crm-forms
Websites are one of the most important sources of leads for your business.
Forms: 3rd-Party Inject Results Developer Profile
13 plugins · 5K total installs
How We Detect Forms: 3rd-Party Inject Results
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.