
FormToEmail Shortcodes Security & Risk Analysis
wordpress.org/plugins/formtoemail-shortcodesAdd FormToEmail forms to any page or post using a shortcode.
Is FormToEmail Shortcodes Safe to Use in 2026?
Generally Safe
Score 85/100FormToEmail Shortcodes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The formtoemail-shortcodes plugin, version 1.0.1, exhibits a generally strong security posture based on the provided static analysis. The absence of direct SQL queries without prepared statements, a high percentage of properly escaped output, and no identified dangerous functions or file operations are positive indicators. Furthermore, the plugin demonstrates good security practices with the presence of nonce checks and a limited attack surface consisting of a single shortcode, which, based on the analysis, appears to be protected.
The taint analysis also reveals no critical or high-severity unsanitized paths, further bolstering its security. The plugin's vulnerability history is notably clean, with zero recorded CVEs of any severity. This lack of past vulnerabilities, combined with the current clean analysis, suggests a developer who is either proactive about security or the plugin has not yet been a target for significant exploitation.
However, the plugin lacks any capability checks for its shortcode. While the static analysis indicates it's not directly exposed to unauthorized access via AJAX or REST API routes, relying solely on nonce checks for shortcode security might be a point of concern if the shortcode handles sensitive data or actions. The absence of capability checks introduces a minor weakness in its otherwise robust security framework, though the overall risk appears low given the limited attack surface and lack of known vulnerabilities.
Key Concerns
- Missing capability checks on shortcode
FormToEmail Shortcodes Security Vulnerabilities
FormToEmail Shortcodes Release Timeline
FormToEmail Shortcodes Code Analysis
Output Escaping
Data Flow Analysis
FormToEmail Shortcodes Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
FormToEmail Shortcodes Maintenance & Trust
Maintenance Signals
Community Trust
FormToEmail Shortcodes Alternatives
Teamgate CRM Forms for WordPress
teamgate-crm-forms
Automate generation of leads to Teamgate CRM by creating contacts, subscriptions or other kind of forms within your WordPress website.
Corymbus Forms
corymbus-forms
Corymbus Forms provides the [corymbus-forms] shortcode which lets you easily embed in your website a web form/page published from the Corymbus CRM.
WP InfusionSoft
wp-infusionsoft
WP Infusionsoft is a plugin for handling web forms created by the popular email marketing site InfusionSoft.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
FormToEmail Shortcodes Developer Profile
1 plugin · 10 total installs
How We Detect FormToEmail Shortcodes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formtoemail-shortcodes/formtoemail.css/wp-content/plugins/formtoemail-shortcodes/logo.png/wp-content/plugins/formtoemail-shortcodes/ace.js/wp-content/plugins/formtoemail-shortcodes/formtoemail.jsformtoemail-shortcodes/formtoemail.css?ver=formtoemail-shortcodes/ace.js?ver=formtoemail-shortcodes/formtoemail.js?ver=HTML / DOM Fingerprints
data-editor="html"[formtoemail id="<img src="plugins_url('logo.png'plugins_url('formtoemail.css'