FormsDeck Security & Risk Analysis

wordpress.org/plugins/formsdeck

Add a beautiful WhatsApp form widget & receive responses from customers on "WhatsApp" and "WhatsApp Business".

0 active installs v1.0.0 PHP 5.5+ WP 4.5.0+ Updated Jun 15, 2025
whatsappwhatsapp-businesswhatsapp-buttonwhatsapp-chatwhatsapp-support
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is FormsDeck Safe to Use in 2026?

Generally Safe

Score 100/100

FormsDeck has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the formsdeck plugin v1.0.0 exhibits a strong security posture. The absence of any identified attack surface points, dangerous functions, direct SQL queries (all are prepared), file operations, or external HTTP requests suggests a well-sanitized codebase. The high percentage of properly escaped output further indicates good development practices for preventing cross-site scripting vulnerabilities.

The vulnerability history is also exceptionally clean, with zero recorded CVEs of any severity. This lack of historical vulnerabilities, combined with the robust static analysis findings, points to a plugin that has either been developed with security as a high priority or has undergone thorough security vetting. However, it's worth noting the complete absence of nonce checks and capability checks. While the current attack surface is zero, if future development introduces new entry points, these checks will be crucial for maintaining security. The lack of taint analysis results (0 flows analyzed) could be due to the limited attack surface or a limitation of the analysis tool's ability to find flows in such a constrained environment. Overall, formsdeck v1.0.0 appears to be a secure plugin, but the lack of explicit authorization checks in its current state is a minor point of attention for potential future expansion.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

FormsDeck Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

FormsDeck Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
20 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped21 total outputs
Attack Surface

FormsDeck Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_enqueue_scriptsformsdeck.php:24
actionadmin_menuformsdeck.php:38
actionadmin_initformsdeck.php:128
actionadmin_initformsdeck.php:141
actionwp_footerformsdeck.php:180
Maintenance & Trust

FormsDeck Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 15, 2025
PHP min version5.5
Downloads821

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

FormsDeck Developer Profile

origyn

3 plugins · 320 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect FormsDeck

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/formsdeck/CSS/admin.css/wp-content/plugins/formsdeck/assets/formsdeck menu icon.svg/wp-content/plugins/formsdeck/formsdeck-logo.png

HTML / DOM Fingerprints

CSS Classes
fd-settings-pagefd-headerfd-logofd-contentleft-panelfd-create-formright-panelfd-feedback+2 more
Data Attributes
data-iddata-message
FAQ

Frequently Asked Questions about FormsDeck