
Contact Form, Survey & Form Builder – MightyForms Security & Risk Analysis
wordpress.org/plugins/mightyformsDrag & drop form builder with lead generation and workflow automation. MightyForms is a contact form builder, survey creator, order form creator, …
Is Contact Form, Survey & Form Builder – MightyForms Safe to Use in 2026?
Generally Safe
Score 91/100Contact Form, Survey & Form Builder – MightyForms has a strong security track record. Known vulnerabilities have been patched promptly.
The MightyForms plugin v1.3.11 exhibits a generally good security posture, with a strong emphasis on secure coding practices. The static analysis reveals no directly exploitable vulnerabilities like dangerous functions or raw SQL queries. The plugin demonstrates excellent output escaping (91%) and utilizes prepared statements for its SQL queries, which are positive indicators. The presence of nonce and capability checks on its limited entry points (AJAX handler and shortcode) further strengthens its defenses against common WordPress attacks.
However, there are a couple of areas that warrant attention. The taint analysis indicates two flows with unsanitized paths, which, although not resulting in critical or high severity issues in this version, represent a potential avenue for future vulnerabilities if not addressed. Additionally, the plugin bundles the DataTables library, which, if outdated or vulnerable, could introduce risks. The vulnerability history shows two past medium-severity CVEs, one related to Missing Authorization and the other to Cross-Site Scripting. While currently unpatched CVEs are zero, the historical pattern suggests a need for ongoing vigilance and prompt patching of any future discovered vulnerabilities.
In conclusion, MightyForms v1.3.11 has a solid foundation of secure coding. The static analysis is largely positive, highlighting good practices in SQL handling and output escaping. The primary concerns stem from the taint analysis findings regarding unsanitized paths and the potential for bundled library vulnerabilities, alongside the historical pattern of past medium-severity CVEs. Continued diligence in code review and timely updates will be crucial for maintaining a secure environment.
Key Concerns
- Taint flow with unsanitized paths
- Bundled library (DataTables)
- Previous medium severity CVEs
Contact Form, Survey & Form Builder – MightyForms Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Contact Form, Survey & Form Builder – MightyForms <= 1.3.9 - Missing Authorization
Contact Form, Survey & Form Builder – MightyForms <= 1.3.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Contact Form, Survey & Form Builder – MightyForms Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Contact Form, Survey & Form Builder – MightyForms Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Contact Form, Survey & Form Builder – MightyForms Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form, Survey & Form Builder – MightyForms Alternatives
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
metform
The most popular Elementor forms builder to create WordPress forms like contact forms, booking forms, feedback form, survey forms, application forms a …
RTMForm Builder
romethemeform
RTMForm For Elementor Plugin is an Form Builder for Elementor, and Widget Ready to use.
Lead Form Builder & Contact Form
lead-form-builder
Fast Drag & Drop Contact From Builder and Lead Generation Tool With Google One Tap Login. Supports Block Editor.
Contact Form by Supsystic
contact-form-by-supsystic
Contact Form Builder with drag-and-drop editor to create responsive, mobile ready contact forms in a second. Custom fields and contact form templates
FormCraft – Form Builder
formcraft-form-builder
Create gorgeous forms for your site using this drag-and-drop form builder.
Contact Form, Survey & Form Builder – MightyForms Developer Profile
1 plugin · 200 total installs
How We Detect Contact Form, Survey & Form Builder – MightyForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mightyforms/images/icon.png/wp-content/plugins/mightyforms/gutenberg_block/init.php/wp-content/plugins/mightyforms/js/script.js/wp-content/plugins/mightyforms/js/jquery.dataTables.min.jshttps://form.mightyforms.com/loader/v1/mightyforms.min.jsmightyforms/js/script.js?ver=mightyforms/css/style.css?ver=mightyforms/js/jquery.dataTables.min.js?ver=mightyforms/css/jquery.dataTables.min.css?ver=https://form.mightyforms.com/loader/v1/mightyforms.min.js?ver=HTML / DOM Fingerprints
mighty-formmf-feedback-icon<!-- MightyForms Section --><!-- End MightyForms Section -->data-rate-actionMF_VERSION<div class="mighty-form" id="