
Kali Forms — Contact Form & Drag-and-Drop Builder Security & Risk Analysis
wordpress.org/plugins/kali-formsBuild contact forms for your WordPress website in minutes through the Drag & Drop builder and Guided Emails for entries notifications.
Is Kali Forms — Contact Form & Drag-and-Drop Builder Safe to Use in 2026?
Generally Safe
Score 88/100Kali Forms — Contact Form & Drag-and-Drop Builder has a strong security track record. Known vulnerabilities have been patched promptly.
The kali-forms plugin v2.4.9 presents a mixed security posture. While it demonstrates strong practices in using prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface. A large number of AJAX handlers (28 out of 41) lack proper authentication checks, creating a substantial entry point for unauthorized actions. Additionally, the taint analysis reveals two flows with unsanitized paths, which, although not flagged as critical or high severity in this analysis, warrant careful investigation as they could be exploited if combined with specific attack vectors.
The plugin's vulnerability history, with 10 known CVEs primarily revolving around Cross-site Scripting and authorization issues, paints a concerning picture of past security weaknesses. The fact that there are currently no unpatched vulnerabilities is a positive sign, but the prevalence of high and medium severity past issues suggests a recurring pattern of authorization and input validation flaws. While the presence of nonce checks and capability checks are good, their effectiveness is diminished by the sheer number of unprotected AJAX endpoints.
In conclusion, kali-forms v2.4.9 has commendable aspects like secure SQL handling and output escaping. However, the significant number of unprotected AJAX handlers and the historical pattern of authorization and XSS vulnerabilities are major red flags. The taint analysis results, though currently low severity, should be viewed with caution given the plugin's history. This plugin requires careful monitoring and potentially further review of its unprotected entry points.
Key Concerns
- High number of unprotected AJAX handlers
- Taint analysis shows unsanitized paths
- Vulnerability history includes high severity XSS and Auth bypass
- Bundled library PHPMailer
Kali Forms — Contact Form & Drag-and-Drop Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
Kali Forms <= 2.4.8 - Insecure Direct Object Reference to Authenticated (Contributor+) Sensitive Form Data Exposure
Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization to Arbitrary Plugin Deactivation
Contact Form builder with drag & drop for WordPress – Kali Forms <= 2.3.41 - Missing Authorization
Contact Form builder with drag & drop - Kali Forms <= 2.3.36 - Insecure Direct Object Reference
Contact Form builder with drag & drop - Kali Forms <= 2.3.27 - Missing Authorization via Contact Form
Contact Form builder with drag & drop - Kali Forms <= 2.3.28 - Missing Authorization via get_log
Kali Forms <= 2.1.1 - Unauthenticated Arbitrary Post Deletion
Kali Forms <= 2.1.1 - Missing Authorization to Settings Update
Kali Forms <= 2.1.1 - Cross-Site Request Forgery
Kali Forms — Contact Form & Drag-and-Drop Builder Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Kali Forms — Contact Form & Drag-and-Drop Builder Attack Surface
AJAX Handlers 41
Shortcodes 2
WordPress Hooks 51
Maintenance & Trust
Kali Forms — Contact Form & Drag-and-Drop Builder Maintenance & Trust
Maintenance Signals
Community Trust
Kali Forms — Contact Form & Drag-and-Drop Builder Alternatives
SureForms – Contact Form, Payment Form & Other Custom Form Builder
sureforms
The most beginner-friendly, AI Form Builder for WordPress to create contact forms, payment forms & other custom forms with advanced features, with …
FormFacade – Embed Google Forms in your website
formfacade
Embed Google Forms™ in your wordpress site
Paperform Form Builder – Contact Forms, Ecommerce And Product Pages, Surveys
paperform-form-builder
Create beautiful branded online forms in Paperform and use this plugin to quickly and easily embed them on multiple WordPress pages and sites.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
Kali Forms — Contact Form & Drag-and-Drop Builder Developer Profile
29 plugins · 440K total installs
How We Detect Kali Forms — Contact Form & Drag-and-Drop Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kali-forms/assets/general/js/general.js/wp-content/plugins/kali-forms/assets/block/js/block.js/wp-content/plugins/kali-forms/assets/block/css/block.csskaliforms/assets/general/js/general.js?ver=kaliforms/assets/block/js/block.js?ver=kaliforms/assets/block/css/block.css?ver=HTML / DOM Fingerprints
kaliforms-containerdata-noncedata-kaliformsKaliFormsGeneralObjectKaliForms/wp-json/kaliforms