
neoForms Security & Risk Analysis
wordpress.org/plugins/neoformsNow you can build form in easiest, simplest and fastest ever way however you want without coding.
Is neoForms Safe to Use in 2026?
Generally Safe
Score 85/100neoForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The neoforms plugin v1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not using dangerous functions, implementing prepared statements for all SQL queries, and not bundling external libraries. The absence of known vulnerabilities in its history is also a positive indicator. However, significant concerns arise from the attack surface. A substantial portion of its AJAX handlers (5 out of 13) lack authentication checks, creating potential entry points for unauthorized actions. Furthermore, only 23% of output escaping is properly implemented, which, combined with the unsanitized path identified in the taint analysis, poses a risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks on AJAX handlers is a critical oversight that exacerbates the risk associated with unprotected entry points.
Key Concerns
- AJAX handlers without authentication
- Low percentage of properly escaped output
- Flow with unsanitized path
- No nonce checks on AJAX
neoForms Security Vulnerabilities
neoForms Release Timeline
neoForms Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
neoForms Attack Surface
AJAX Handlers 13
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
neoForms Maintenance & Trust
Maintenance Signals
Community Trust
neoForms Alternatives
Ninja Forms – The Contact Form Builder That Grows With You
ninja-forms
The 100% beginner friendly WordPress form builder. Drag & drop form fields to build beautiful, professional contact forms in minutes.
Affiliate Contact Form 7 Integration For WooCommerce
affiliate-contact-form-7-integration-for-woocommerce
Recruit better affiliates for your affiliate program by gathering detailed insights through Contact Form 7 (CF7) powered custom registration forms.
Vedrixa Forms – Contact Form, Registration Form & Drag-and-Drop Form Builder
vedrixa-forms-registration-builder
Build contact and registration forms with a drag-and-drop WordPress form builder and submission manager.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
neoForms Developer Profile
17 plugins · 490 total installs
How We Detect neoForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/neoforms/assets/js/neoforms-admin.js/wp-content/plugins/neoforms/assets/css/neoforms-admin.css/wp-content/plugins/neoforms/assets/js/neoforms-front.js/wp-content/plugins/neoforms/assets/css/neoforms-front.css/wp-content/plugins/neoforms/assets/js/neoforms-admin.js/wp-content/plugins/neoforms/assets/js/neoforms-front.jsneoforms/assets/css/neoforms-admin.css?ver=neoforms/assets/js/neoforms-admin.js?ver=neoforms/assets/css/neoforms-front.css?ver=neoforms/assets/js/neoforms-front.js?ver=HTML / DOM Fingerprints
neoforms-form-builder-wrapperneoforms-admin-menu-wrapperneoforms-form-elementneoforms-field-wrapperdata-neoforms-field-typedata-neoforms-field-idneoforms_global_data[neoforms-form id=""]