
Formzu WP Security & Risk Analysis
wordpress.org/plugins/formzu-wpメールフォーム無料作成サービス「フォームズ」のSSL通信フォームを簡単に設置できます。
Is Formzu WP Safe to Use in 2026?
Generally Safe
Score 99/100Formzu WP has a strong security track record. Known vulnerabilities have been patched promptly.
The "formzu-wp" plugin v1.6.11 presents a mixed security posture. On the positive side, it utilizes prepared statements for all SQL queries and includes a reasonable number of nonce and capability checks. However, the presence of an unprotected AJAX handler significantly increases the attack surface, making it a primary concern. The taint analysis reveals flows with unsanitized paths, indicating potential for vulnerabilities if these flows are not handled carefully, although no critical or high severity issues were flagged in the static analysis. The plugin's vulnerability history shows two medium severity CVEs, both of which are now patched. The common vulnerability type being Cross-site Scripting is a recurring pattern. Overall, while the plugin demonstrates some good security practices, the unprotected AJAX endpoint and history of XSS vulnerabilities warrant caution and ongoing monitoring.
Key Concerns
- Unprotected AJAX handler
- Significant percentage of unescaped output
- Taint analysis shows unsanitized paths
- History of medium severity XSS vulnerabilities
Formzu WP Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Formzu WP <= 1.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
Formzu WP <= 1.6.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via id
Formzu WP Code Analysis
Output Escaping
Data Flow Analysis
Formzu WP Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 27
Maintenance & Trust
Formzu WP Maintenance & Trust
Maintenance Signals
Community Trust
Formzu WP Alternatives
Contact Form 7
contact-form-7
Just another contact form plugin. Simple but flexible.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
Formzu WP Developer Profile
1 plugin · 3K total installs
How We Detect Formzu WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/formzu-wp/js/formzu.js/wp-content/plugins/formzu-wp/css/formzu.css/wp-content/plugins/formzu-wp/includes/js/formzu-navmenu.js/wp-content/plugins/formzu-wp/includes/js/formzu-tour.js/wp-content/plugins/formzu-wp/admin/js/formzu-admin.js/wp-content/plugins/formzu-wp/admin/js/formzu-widgetmenu.js/wp-content/plugins/formzu-wp/admin/js/formzu-howtouse.js/wp-content/plugins/formzu-wp/admin/js/formzu-create.js+1 morehttps://ws.formzu.net/dist/formzu.jsformzu-wp/js/formzu.js?ver=formzu-wp/css/formzu.css?ver=formzu-wp/includes/js/formzu-navmenu.js?ver=formzu-wp/includes/js/formzu-tour.js?ver=formzu-wp/admin/js/formzu-admin.js?ver=formzu-wp/admin/js/formzu-widgetmenu.js?ver=formzu-wp/admin/js/formzu-howtouse.js?ver=formzu-wp/admin/js/formzu-create.js?ver=formzu-wp/admin/js/formzu-form.js?ver=HTML / DOM Fingerprints
formzu-form-wrap<!-- formzu-nav-metabox --><!-- formzu-nav-select --><!-- formzu-nav-submit -->data-formzu-idformzu_navmenu_paramsformzu_navmenu_nonce_field[formzu]