
The Innovative Form Builder – IvyForms Security & Risk Analysis
wordpress.org/plugins/ivyformsThe most innovative WordPress Form Builder plugin. Build awesome contact, order, registration, custom forms, and more in minutes.
Is The Innovative Form Builder – IvyForms Safe to Use in 2026?
Generally Safe
Score 100/100The Innovative Form Builder – IvyForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ivyforms" plugin v0.9.1 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices with a high percentage of SQL queries using prepared statements and properly escaped output. The plugin also has a clean vulnerability history, with no known CVEs recorded, suggesting a generally robust development and maintenance process.
However, there are significant concerns regarding its attack surface. The plugin exposes two AJAX handlers that lack authentication checks, presenting a clear entry point for unauthenticated attackers. The presence of the `unserialize` function, a known risky function, also raises a flag, especially if its input is not meticulously validated. While the taint analysis shows no critical or high-severity flows, the lack of authentication on AJAX endpoints coupled with the `unserialize` function creates potential for exploitation if attacker-controlled data can reach these functions.
In conclusion, while "ivyforms" benefits from good coding practices in areas like SQL and output handling, and has no historical vulnerabilities, the unprotected AJAX endpoints and the use of `unserialize` represent notable security weaknesses. These issues should be prioritized for remediation to enhance the plugin's overall security.
Key Concerns
- Unprotected AJAX handlers
- Dangerous function: unserialize
The Innovative Form Builder – IvyForms Security Vulnerabilities
The Innovative Form Builder – IvyForms Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
The Innovative Form Builder – IvyForms Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 18
Maintenance & Trust
The Innovative Form Builder – IvyForms Maintenance & Trust
Maintenance Signals
Community Trust
The Innovative Form Builder – IvyForms Alternatives
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
FormGlut — Contact, Newsletter & Multi-step Form Builder
formglut
User friendly, Lightweight, Drag & Drop form builder to create your WordPress Forms
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
metform
The most popular Elementor forms builder to create WordPress forms like contact forms, booking forms, feedback form, survey forms, application forms a …
SureForms – Contact Form, Payment Form & Other Custom Form Builder
sureforms
The most beginner-friendly, AI Form Builder for WordPress to create contact forms, payment forms & other custom forms with advanced features, with …
The Innovative Form Builder – IvyForms Developer Profile
3 plugins · 71K total installs
How We Detect The Innovative Form Builder – IvyForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ivyforms/frontend/assets/css/global-admin.css/wp-content/plugins/ivyforms/frontend/assets/js/admin-deactivation-modal.js/wp-content/plugins/ivyforms/frontend/assets/js/admin-deactivation-modal.jsivyforms/style.css?ver=ivyforms-deactivation-modal?ver=ivyforms_admin_global?ver=HTML / DOM Fingerprints
ivyforms-fullscreen-modedata-ivyforms-blockivyformsData/ivyforms/v1/deactivation-feedback