
Forms Rb Security & Risk Analysis
wordpress.org/plugins/forms-rbForms Rb - the most simple way to create a hosted form, contact form, order form, support form. Simple contact form setup and form fields management
Is Forms Rb Safe to Use in 2026?
Generally Safe
Score 100/100Forms Rb has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'forms-rb' plugin v1.1.9 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin has a small attack surface, with only one shortcode and no unprotected entry points identified. Crucially, there are no dangerous functions, no raw SQL queries, and no external HTTP requests, all of which are excellent security indicators. The output escaping is also reasonably good at 72%.
However, a significant concern is the complete absence of nonce checks across all identified entry points. While the plugin does have one capability check, the lack of nonce validation on the shortcode could potentially expose it to cross-site request forgery (CSRF) attacks if the shortcode's functionality is sensitive. The taint analysis showing zero flows is positive, but the absence of nonce checks remains a notable weakness that could be exploited.
With no recorded vulnerabilities or CVEs, the plugin's historical security record is clean. This suggests a diligent development process. Overall, 'forms-rb' v1.1.9 is likely a secure plugin, but the lack of nonce checks on its shortcode is a weakness that warrants attention to mitigate potential CSRF risks.
Key Concerns
- Missing nonce checks on shortcode
- Output escaping not 100%
Forms Rb Security Vulnerabilities
Forms Rb Code Analysis
Output Escaping
Forms Rb Attack Surface
Shortcodes 1
WordPress Hooks 15
Scheduled Events 1
Maintenance & Trust
Forms Rb Maintenance & Trust
Maintenance Signals
Community Trust
Forms Rb Alternatives
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress
wpzoom-forms
Drag & drop contact form builder for WordPress. Create contact forms, custom forms, email forms with spam protection. Works with Elementor, shortcodes
VPSUForm – Drag & Drop Contact Form Builder with Email Automation
v-form
A lightweight drag-and-drop WordPress form builder with email automation, conditional logic, spam protection, and full lead management.
OmniForm
omniform
Easily create and manage custom forms with the block editor, customizable fields, and form submission management for your website.
GenForm – Drag & Drop Form Builder
genform
The lightweight drag-and-drop form builder for WordPress. Create contact forms, feedback forms, bookings, and more — no coding required.
Weavely – Build Forms in Figma
weavely
Turn Figma designs into custom forms, effortlessly embed in WordPress. Elevate user experience with unique designs.
Forms Rb Developer Profile
8 plugins · 107K total installs
How We Detect Forms Rb
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/forms-rb/assets/main.js/wp-content/plugins/forms-rb/assets/main.jsforms-rb/assets/main.js?ver=HTML / DOM Fingerprints
rb_contact_formrbform_idrbforms_config_formid_[rbform