
Multi-step Forms FREE (for Elementor) Security & Risk Analysis
wordpress.org/plugins/multi-step-forms-free-for-elementorA simple plugin that streamlines the creation of multistep (or multiple page) forms to an easy drag-and-drop through the power of Elementor Pro.
Is Multi-step Forms FREE (for Elementor) Safe to Use in 2026?
Generally Safe
Score 85/100Multi-step Forms FREE (for Elementor) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "multi-step-forms-free-for-elementor" v1.2.4 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, performing all SQL queries using prepared statements, and having no recorded vulnerabilities or CVEs. However, significant concerns arise from the static analysis. The plugin exposes a single REST API route without any permission checks, creating a substantial attack vector. Furthermore, a critical 96% of its output is not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks on its single entry point exacerbates these issues, making it vulnerable to various attacks if an attacker can trigger the REST API endpoint.
While the lack of known vulnerabilities is a positive indicator, it may be attributed to its relatively small attack surface and the potential for undiscovered issues due to the high percentage of unescaped output. The absence of taint analysis flows is also noted, which could mean that either no flows were analyzed or that no critical/high severity flows were detected. Overall, the plugin has a strong foundation with regards to data handling (SQL), but the lack of input validation and output escaping on its exposed REST API endpoint presents a significant, actionable security risk.
Key Concerns
- REST API route without permission callback
- High percentage of unescaped output
- No nonce checks on entry points
- No capability checks on entry points
Multi-step Forms FREE (for Elementor) Security Vulnerabilities
Multi-step Forms FREE (for Elementor) Code Analysis
Output Escaping
Multi-step Forms FREE (for Elementor) Attack Surface
REST API Routes 1
WordPress Hooks 8
Maintenance & Trust
Multi-step Forms FREE (for Elementor) Maintenance & Trust
Maintenance Signals
Community Trust
Multi-step Forms FREE (for Elementor) Alternatives
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
TemplateSpare – 1000+ WordPress Starter Templates & Full Site Migration Tool | 1-Click Import/Export & No-Code Builder
templatespare
Imagine this... You’re planning your new website. You’re excited at first—but then reality hits. The design takes months. You wait for the developer t …
DragDropr – Visual Drag & Drop Page Builder
dragdropr
DragDropr is a What-You-See-Is-What-You-REALLY-Get visual editor.
Page builder for Posts – Mong9 Editor
mong9-editor
The most advanced frontend drag & drop content editor. Mong9 Editor is a responsive page builder which can be used to extend the Classic Editor.
Widgets Testimonial DT
widgets-testimonial-dt
add a block of testimonials to the web page, this plugin needs the previous installation of Elementor
Multi-step Forms FREE (for Elementor) Developer Profile
1 plugin · 20 total installs
How We Detect Multi-step Forms FREE (for Elementor)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/multi-step-forms-free-for-elementor/assets/js/editor.js/wp-content/plugins/multi-step-forms-free-for-elementor/admin/css/multi-step-forms-free-admin.css/wp-content/plugins/multi-step-forms-free-for-elementor/admin/js/multi-step-forms-free-admin.jsassets/js/editor.jsadmin/js/multi-step-forms-free-admin.jsmulti-step-forms-free-for-elementor/admin/css/multi-step-forms-free-admin.css?ver=multi-step-forms-free-for-elementor/admin/js/multi-step-forms-free-admin.js?ver=HTML / DOM Fingerprints
elementorMultistepFreemultistep_plugin_url_freecorona_monitor/v1/update