
Nelio Forms Security & Risk Analysis
wordpress.org/plugins/nelio-formsAn intuitive form builder based on open WordPress technologies
Is Nelio Forms Safe to Use in 2026?
Generally Safe
Score 100/100Nelio Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of Nelio Forms v1.2.0 indicates a generally strong security posture. The plugin has no critical or high severity taint flows, uses prepared statements for all SQL queries, and properly escapes a high percentage of its output. The absence of external HTTP requests and the handling of file operations are also positive signs. Furthermore, the plugin's vulnerability history is clean, with no recorded CVEs, suggesting a commitment to security and code quality by the developers.
However, there are areas for improvement. The presence of a shortcode without explicit authentication checks is a potential entry point that, while not currently flagged as problematic in taint analysis, could be a target if vulnerabilities are introduced in the future. The lack of nonce checks on the identified AJAX handlers, though there are none currently, implies a potential oversight that could be exploited if AJAX functionality is added or modified without proper security measures. The presence of capability checks, while good, could be more comprehensive if they are not consistently applied to all sensitive operations.
Overall, Nelio Forms v1.2.0 appears to be a well-developed plugin with a focus on secure coding practices. The lack of known vulnerabilities and the good results from static analysis are reassuring. The primary recommendation is to ensure that any future additions of AJAX handlers or shortcodes include robust authentication and authorization checks to maintain this strong security posture.
Key Concerns
- Shortcode without auth check
- No nonce checks on AJAX handlers (potential)
Nelio Forms Security Vulnerabilities
Nelio Forms Code Analysis
Output Escaping
Nelio Forms Attack Surface
Shortcodes 1
WordPress Hooks 78
Maintenance & Trust
Nelio Forms Maintenance & Trust
Maintenance Signals
Community Trust
Nelio Forms Alternatives
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress
wpzoom-forms
Drag & drop contact form builder for WordPress. Create contact forms, custom forms, email forms with spam protection. Works with Elementor, shortcodes
Contact Form Widget
new-contact-form-widget
Create contact forms with query table management. Simple setup, secure submissions, and easy customization for your site.
Quick Contact Form
quick-contact-form
An easy to set up, plug and play contact form with a huge range of options and styles. A beginner friendly WordPress contact form plugin.
Contact Forms by Cimatti
contact-forms
Create and publish forms in your WordPress website with drag and drop. Contact forms, landing page forms, invitations, and more.
More Mails for CF7
more-mails-for-cf7
Extends the ubiquitous Contact Form 7 plugin to allow three or more messages.
Nelio Forms Developer Profile
12 plugins · 11K total installs
How We Detect Nelio Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nelio-forms/dist/opinionated-style.css/wp-content/plugins/nelio-forms/dist/form-style.css/wp-content/plugins/nelio-forms/dist/form-view-script.jsnelio-forms/dist/opinionated-style.css?ver=nelio-forms/dist/form-style.css?ver=nelio-forms/dist/form-view-script.js?ver=HTML / DOM Fingerprints
nelio-forms-formnelio-forms-fieldnelio-forms-field--hiddennelio-forms-field__labelnelio-forms-field__label--textnelio-forms-field__valuenelio-forms-field__value--textnelio-forms-error-noscript<!-- wp:nelio-forms/form {"ref":<!-- text -->data-formiddata-submit-processing-labeldata-hide-formNelioFormsErrorMessages[nelio-form id="<!-- wp:nelio-forms/form {"ref":<formmethod="post"