HT Form Widget for Elementor and WPForms Security & Risk Analysis

wordpress.org/plugins/ht-wpform

HT Form Widget for Elementor and WPForms allows you to easily display WPForms forms using Elementor with full styling control.

3K active installs v1.1.6 PHP + WP 5.0+ Updated Apr 21, 2025
contact-formelementorelementor-addonform-widgetwpforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HT Form Widget for Elementor and WPForms Safe to Use in 2026?

Generally Safe

Score 100/100

HT Form Widget for Elementor and WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The ht-wpform plugin v1.1.6 demonstrates a generally strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Furthermore, the plugin successfully avoids dangerous functions and file operations, and all SQL queries are properly prepared. The vulnerability history also shows no recorded CVEs, suggesting a history of secure development or diligent patching.

However, a significant concern arises from the output escaping analysis, where 0% of the identified outputs are properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied or dynamic data could be rendered directly in the browser without sanitization, allowing attackers to inject malicious scripts. While the plugin has a clean vulnerability history, the lack of output escaping presents an immediate and critical risk that needs addressing.

Key Concerns

  • 0% of outputs properly escaped
Vulnerabilities
None known

HT Form Widget for Elementor and WPForms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

HT Form Widget for Elementor and WPForms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Attack Surface

HT Form Widget for Elementor and WPForms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitinclude\base.php:21
actionplugins_loadedinclude\base.php:22
actionadmin_noticesinclude\base.php:36
actionadmin_noticesinclude\base.php:42
actionadmin_noticesinclude\base.php:48
actionadmin_noticesinclude\base.php:55
actionelementor/widgets/widgets_registeredinclude\base.php:61
Maintenance & Trust

HT Form Widget for Elementor and WPForms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 21, 2025
PHP min version
Downloads56K

Community Trust

Rating80/100
Number of ratings1
Active installs3K
Developer Profile

HT Form Widget for Elementor and WPForms Developer Profile

HT Plugins

23 plugins · 64K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
124 days
View full developer profile
Detection Fingerprints

How We Detect HT Form Widget for Elementor and WPForms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ht-wpform/assets/css/ht-wpform-public.css/wp-content/plugins/ht-wpform/assets/js/ht-wpform-public.js
Script Paths
/wp-content/plugins/ht-wpform/assets/js/ht-wpform-public.js
Version Parameters
ht-wpform/assets/css/ht-wpform-public.css?ver=ht-wpform/assets/js/ht-wpform-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
htwpf-form-wrapper
FAQ

Frequently Asked Questions about HT Form Widget for Elementor and WPForms