
Forms: 3rd-Party File Attachments Security & Risk Analysis
wordpress.org/plugins/forms-3rdparty-filesAdd file upload processing to Forms 3rdparty Integration.
Is Forms: 3rd-Party File Attachments Safe to Use in 2026?
Generally Safe
Score 85/100Forms: 3rd-Party File Attachments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'forms-3rdparty-files' plugin v0.5.2 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by having no known CVEs and no recorded vulnerabilities, suggesting a generally secure development history. The static analysis also shows no dangerous functions, no external HTTP requests, and all SQL queries using prepared statements, which are strong indicators of security awareness. However, significant concerns arise from the complete lack of nonce and capability checks across all potential entry points, coupled with a very low percentage (12%) of properly escaped output. This means that while the plugin might not have actively exploited vulnerabilities in the past, it has a substantial inherent risk of Cross-Site Request Forgery (CSRF) and potential Cross-Site Scripting (XSS) vulnerabilities due to insufficient input validation and output sanitization. The file operations signal also warrants attention, although without further context, its specific risk is unclear. The absence of any taint analysis results is also noteworthy, potentially indicating that the analysis tool was not able to trace any data flows or that such flows were deemed insignificant, but this could also be a limitation of the analysis itself.
Key Concerns
- No nonce checks on any entry points
- No capability checks on any entry points
- Low percentage of properly escaped output
- Presence of file operations (unspecified risk)
Forms: 3rd-Party File Attachments Security Vulnerabilities
Forms: 3rd-Party File Attachments Code Analysis
Output Escaping
Forms: 3rd-Party File Attachments Attack Surface
WordPress Hooks 1
Maintenance & Trust
Forms: 3rd-Party File Attachments Maintenance & Trust
Maintenance Signals
Community Trust
Forms: 3rd-Party File Attachments Alternatives
Forms: 3rd-Party Integration
forms-3rdparty-integration
Send contact form submissions from other plugins to multiple external services e.g. CRM. Configurable, custom field mapping, pre/post processing.
Autopreenchimento de endereço em formulários
cf7-cep-autofill
Preenchimento automático de campos de endereço baseado no CEP informado.
Forms: 3rd-Party Xml Post
forms-3rd-party-xpost
Converts submission from Forms 3rdparty Integration to xml/json, add headers, or nest fields.
Forms: 3rd-Party Dynamic Fields
forms-3rdparty-dynamic-fields
Using pre-configured placeholders like ##UID##, ##REFERER##, or ##SITEURL##, add dynamic fields to the normally map-only or static-only Forms: 3rdpart …
Forms: 3rd-Party Migration
forms-3rdparty-migrate
To upgrade deprecated Wordpress Plugin CF7-3rdparty Integration to the new version Forms 3rdparty Integration, or migrate settings of either plugin be …
Forms: 3rd-Party File Attachments Developer Profile
13 plugins · 5K total installs
How We Detect Forms: 3rd-Party File Attachments
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/forms-3rdparty-files/css/f3if.css/wp-content/plugins/forms-3rdparty-files/js/f3if.js/wp-content/plugins/forms-3rdparty-files/js/f3if.jsforms-3rdparty-files/css/f3if.css?ver=forms-3rdparty-files/js/f3if.js?ver=HTML / DOM Fingerprints
name="f3if_how"name="f3if_gf"name="forms-3rdparty-files[options][how]"name="forms-3rdparty-files[options][gf]"