
NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Security & Risk Analysis
wordpress.org/plugins/nativeformsBuild forms, surveys & polls for WordPress. Add forms to your website in few minutes and start getting more from your visitors.
Is NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Safe to Use in 2026?
Generally Safe
Score 85/100NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the nativeforms plugin version 1.0.2 exhibits a strong security posture. The absence of dangerous functions, proper escaping of all outputs, and the use of prepared statements for all SQL queries are excellent practices. The plugin also demonstrates a focus on security by implementing capability checks for its entry point and having no identified vulnerabilities or CVEs. The limited attack surface, consisting solely of a single shortcode with a capability check, further reinforces its security. However, the complete lack of nonce checks, while not immediately concerning given the single, permission-checked shortcode, could represent a missed opportunity for defense-in-depth, especially if the shortcode's functionality were to become more complex or handle sensitive data in future versions. The absence of taint analysis results is also notable, suggesting either the code was too simple to trigger analysis or potentially that more complex data flows were not thoroughly examined. Overall, the plugin appears secure for its current version and feature set, but a review of nonce implementation could enhance its resilience.
Key Concerns
- Missing nonce checks on shortcodes
NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Security Vulnerabilities
NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Code Analysis
Output Escaping
NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Attack Surface
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Maintenance & Trust
Maintenance Signals
Community Trust
NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Alternatives
Crowdsignal Forms
crowdsignal-forms
The Crowdsignal Forms plugin allows you to create and manage polls right from within the block editor.
NgSurvey – Powerful, feature rich self-hosted surveys
ngsurvey
Create rich and powerful surveys in minutes. conditional/skip logic, advanced reports, statistics and many more features out of the box.
Dynamic Surveys
dynamic-surveys
Create and manage simple surveys with real-time results display using beautiful pie charts.
SH Advance Polls
sh-advance-polls
You can create polls and surveys for your audience and observe the full analytics in the admin panel.
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
forminator
Best WordPress form builder plugin. Create contact forms, payment forms & order forms with 1000+ integrations.
NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Developer Profile
1 plugin · 40 total installs
How We Detect NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nativeforms/admin.js/wp-content/plugins/nativeforms/classic.jshttps://script.nativeforms.com/main.jsHTML / DOM Fingerprints
nf-resizable-formwp-block-dodel-nativeforms-blockblock-of-formdata-form-id<iframe src="https://form.nativeforms.com/" width="100%" height="600" frameborder="0" class="nf-resizable-form" > </iframe>