NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Security & Risk Analysis

wordpress.org/plugins/nativeforms

Build forms, surveys & polls for WordPress. Add forms to your website in few minutes and start getting more from your visitors.

40 active installs v1.0.2 PHP 5.2.4+ WP 4.7+ Updated Nov 13, 2021
formsnpspaymentpollssurveys
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Safe to Use in 2026?

Generally Safe

Score 85/100

NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the nativeforms plugin version 1.0.2 exhibits a strong security posture. The absence of dangerous functions, proper escaping of all outputs, and the use of prepared statements for all SQL queries are excellent practices. The plugin also demonstrates a focus on security by implementing capability checks for its entry point and having no identified vulnerabilities or CVEs. The limited attack surface, consisting solely of a single shortcode with a capability check, further reinforces its security. However, the complete lack of nonce checks, while not immediately concerning given the single, permission-checked shortcode, could represent a missed opportunity for defense-in-depth, especially if the shortcode's functionality were to become more complex or handle sensitive data in future versions. The absence of taint analysis results is also notable, suggesting either the code was too simple to trigger analysis or potentially that more complex data flows were not thoroughly examined. Overall, the plugin appears secure for its current version and feature set, but a review of nonce implementation could enhance its resilience.

Key Concerns

  • Missing nonce checks on shortcodes
Vulnerabilities
None known

NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[native-forms] nativeforms.php:27
WordPress Hooks 10
actionadmin_menunativeforms.php:20
actionenqueue_block_editor_assetsnativeforms.php:21
actionwp_enqueue_scriptsnativeforms.php:22
actionwp_footernativeforms.php:23
actionadmin_enqueue_scriptsnativeforms.php:24
actionafter_setup_themenativeforms.php:25
actionadmin_footernativeforms.php:26
filtermce_external_pluginsnativeforms.php:75
filtermce_buttonsnativeforms.php:76
actioninitnativeforms.php:80
Maintenance & Trust

NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedNov 13, 2021
PHP min version5.2.4
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs40
Developer Profile

NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms Developer Profile

nativeforms

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nativeforms/admin.js/wp-content/plugins/nativeforms/classic.js
Script Paths
https://script.nativeforms.com/main.js

HTML / DOM Fingerprints

CSS Classes
nf-resizable-formwp-block-dodel-nativeforms-blockblock-of-form
Data Attributes
data-form-id
Shortcode Output
<iframe src="https://form.nativeforms.com/" width="100%" height="600" frameborder="0" class="nf-resizable-form" > </iframe>
FAQ

Frequently Asked Questions about NativeForms – Contact, NPS, Payment, Feedback, Newsletter Forms