
Formstack Online Forms Security & Risk Analysis
wordpress.org/plugins/formstackThis plugin allows you to easily embed Web forms built with Formstack's online form builder into your sidebar, pages, and posts.
Is Formstack Online Forms Safe to Use in 2026?
Use With Caution
Score 63/100Formstack Online Forms has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The Formstack plugin v2.0.2 exhibits a mixed security posture. On the positive side, the static analysis reveals no overtly dangerous functions and all SQL queries utilize prepared statements, which is a strong indicator of secure database interaction. The output escaping is also robust at 85%, minimizing the risk of cross-site scripting vulnerabilities. However, there are notable areas of concern. The presence of one flow with an unsanitized path, although not classified as critical or high severity, warrants attention as it could indicate potential for path traversal or other file system related vulnerabilities. The complete lack of nonce checks and capability checks, especially given the plugin's potential interactions with external services (indicated by 7 external HTTP requests), is a significant weakness. This absence of authorization checks on potential entry points can expose the plugin to unauthorized actions if new vulnerabilities are introduced or if existing ones are exploited. The vulnerability history indicates a pattern of missing authorization issues, with a medium severity CVE recorded recently. While the plugin has a history of a single medium CVE, the recent date of the last vulnerability (2025-12-05) combined with the lack of authorization checks in the current version suggests a recurring theme and a potential blind spot in the plugin's security development lifecycle.
Key Concerns
- Unpatched CVE detected
- Flow with unsanitized path
- Missing nonce checks
- Missing capability checks
- Bundled outdated library (TinyMCE)
Formstack Online Forms Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Formstack Online Forms <= 2.0.2 - Missing Authorization
Formstack Online Forms Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Formstack Online Forms Attack Surface
WordPress Hooks 11
Maintenance & Trust
Formstack Online Forms Maintenance & Trust
Maintenance Signals
Community Trust
Formstack Online Forms Alternatives
WS Form LITE – Drag & Drop Contact Form Builder
ws-form
Contact form builder for WordPress. Create professional, accessible, mobile-friendly forms in minutes without coding.
Formsite | Embed online forms to collect orders, registrations, leads, and surveys
formsite
Embed online forms and surveys from Formsite into pages, posts, and sidebars with an easy shortcode.
GoZen Engage
gozen-engage
GoZen Engage is a AI-Powered Interactive Content And Gamification
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
Formstack Online Forms Developer Profile
1 plugin · 1K total installs
How We Detect Formstack Online Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formstack/assets/formstack-admin.css/wp-content/plugins/formstack/assets/formstack-admin.js//www.formstack.com/forms/css/2/wordpress-post.cssHTML / DOM Fingerprints
formstack_client_idformstack_client_secretformstack_settingsformstack_formsformstack_tinymce