
Contact Form By Mega Forms – Drag and Drop Form Builder Security & Risk Analysis
wordpress.org/plugins/mega-formsContact form builder that allows you to create forms for any purpose. Drag & drop form fields to build modern, professional contact forms in minutes.
Is Contact Form By Mega Forms – Drag and Drop Form Builder Safe to Use in 2026?
Generally Safe
Score 98/100Contact Form By Mega Forms – Drag and Drop Form Builder has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin 'mega-forms' v1.6.9 presents a mixed security posture. While it demonstrates good practices in SQL query preparation (74%) and output escaping (64%), significant concerns arise from its attack surface. All 5 identified AJAX handlers lack proper authentication checks, making them prime targets for unauthorized actions. The taint analysis, while not revealing critical or high severity issues, did identify 6 flows with unsanitized paths, indicating a potential for vulnerabilities if malicious data is introduced. The vulnerability history shows a past pattern of Missing Authorization and Cross-site Scripting vulnerabilities, reinforcing the risk associated with the unprotected AJAX endpoints. Although there are no currently unpatched CVEs, the historical trend and the static analysis findings suggest a need for immediate attention to the lack of authorization checks on AJAX handlers to mitigate potential security risks.
Key Concerns
- High attack surface without auth checks on AJAX
- 6 unsanitized paths in taint analysis
- Past vulnerabilities: Missing Authorization
- Past vulnerabilities: XSS
- Only 1 nonce check for 5 AJAX handlers
- Only 4 capability checks for 5 AJAX handlers
Contact Form By Mega Forms – Drag and Drop Form Builder Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Contact Form By Mega Forms <= 1.6.1 - Missing Authorization
Contact Form By Mega Forms <= 1.2.4 - Authenticated (Subscriber+) Stored Cross-Site Scripting
Contact Form By Mega Forms – Drag and Drop Form Builder Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Contact Form By Mega Forms – Drag and Drop Form Builder Attack Surface
AJAX Handlers 5
WordPress Hooks 43
Scheduled Events 1
Maintenance & Trust
Contact Form By Mega Forms – Drag and Drop Form Builder Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form By Mega Forms – Drag and Drop Form Builder Alternatives
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
forminator
Best WordPress form builder plugin. Create contact forms, payment forms & order forms with 1000+ integrations.
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
metform
The most popular Elementor forms builder to create WordPress forms like contact forms, booking forms, feedback form, survey forms, application forms a …
SureForms – Contact Form, Payment Form & Other Custom Form Builder
sureforms
The most beginner-friendly, AI Form Builder for WordPress to create contact forms, payment forms & other custom forms with advanced features, with …
Contact Form By Mega Forms – Drag and Drop Form Builder Developer Profile
3 plugins · 340 total installs
How We Detect Contact Form By Mega Forms – Drag and Drop Form Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mega-forms/admin/assets/css/deps/snackbar.min.css/wp-content/plugins/mega-forms/admin/assets/css/deps/select2.min.css/wp-content/plugins/mega-forms/assets/admin/css/styles.min.css/wp-content/plugins/mega-forms/admin/assets/js/deps/snackbar.min.js/wp-content/plugins/mega-forms/admin/assets/js/deps/select2.min.jsmega-forms/assets/admin/css/styles.min.css?ver=mega-forms/admin/assets/css/deps/snackbar.min.css?ver=mega-forms/admin/assets/css/deps/select2.min.css?ver=mega-forms/admin/assets/js/deps/snackbar.min.js?ver=mega-forms/admin/assets/js/deps/select2.min.js?ver=HTML / DOM Fingerprints
mf_pagemegaforms-admin-wrapThe code that runs during plugin activation.The code that runs during plugin deactivation.The code that runs on plugin unistallation.Check if the plugin database was updated and perform any necessary actions.+13 moredata-mf-namedata-mf-slugmf_apimfVars