
Neoforum Security & Risk Analysis
wordpress.org/plugins/neoforumNeoforum is full-fledged forum engine for Wordpress, including all standard forum functionality.
Is Neoforum Safe to Use in 2026?
High Risk
Score 41/100Neoforum carries significant security risk with 2 known CVEs, 2 still unpatched. Consider switching to a maintained alternative.
The neoforum plugin v1.0 presents a concerning security posture despite some positive indicators. The presence of 4 unprotected AJAX handlers is a significant immediate risk, allowing potential unauthorized actions. The high number of unsanitized paths identified in taint analysis (35 high severity flows) directly correlates with the historical vulnerability types of XSS and SQL Injection, indicating persistent and likely exploitable weaknesses within the code. While the plugin does utilize nonce checks and capability checks, the low percentage of prepared SQL statements (4%) and properly escaped output (17%) suggests that even with these safeguards, malicious input could still lead to data compromise.
The vulnerability history, with 2 unpatched medium severity CVEs, further reinforces the notion that the plugin has a track record of security flaws, and the recent date of the last vulnerability suggests these issues are not being proactively addressed. The plugin has a moderate attack surface with 64 entry points. While there are no REST API routes or cron events that are unprotected, the unprotected AJAX handlers are a critical concern.
In conclusion, while neoforum v1.0 has some basic security practices in place, the significant number of unsanitized taint flows, the lack of widespread prepared SQL statements and output escaping, and a history of unpatched vulnerabilities paint a picture of a plugin that requires immediate attention. The unprotected AJAX handlers are a critical vulnerability that should be prioritized for remediation.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized paths in taint analysis
- Low percentage of prepared SQL statements
- Low percentage of properly escaped output
- Unpatched CVEs (2 medium)
Neoforum Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Neoforum <= 1.0 - Reflected Cross-Site Scripting
Neoforum <= 1.0 - Authenticated (Administrator+) SQL Injection
Neoforum Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Neoforum Attack Surface
AJAX Handlers 63
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Neoforum Maintenance & Trust
Maintenance Signals
Community Trust
Neoforum Alternatives
wpForo Forum
wpforo
Number one WordPress forum plugin. Full-fledged forum solution with modern and responsive forum design. Community builder WordPress forum plugin.
Asgaros Forum
asgaros-forum
Asgaros Forum is the best forum-plugin for WordPress! It comes with dozens of features in a beautiful design and stays simple and fast.
Discussion Board – WordPress Forum Plugin
wp-discussion-board
Discussion Board is a simple, effective way to add a forum or discussion board to your site, helping you build and engage an active community.
Forumax – AI Powered Advanced Community Forum Plugin
bbp-core
Build powerful communities with Forumax. A fully standalone, feature-rich forum plugin with voting, private replies, and Elementor integration.
Ultimate Member – ForumWP forum integration
um-forumwp
Integrate Ultimate Member with the forum plugin ForumWP.
Neoforum Developer Profile
1 plugin · 0 total installs
How We Detect Neoforum
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/neoforum/nf-admin/js/main-page.js/wp-content/plugins/neoforum/nf-admin/js/forums.js/wp-content/plugins/neoforum/nf-admin/js/trash.js/wp-content/plugins/neoforum/nf-admin/js/users.js/wp-content/plugins/neoforum/nf-admin/js/reports.jsnf-admin/js/main-page.jsnf-admin/js/forums.jsnf-admin/js/trash.jsnf-admin/js/users.jsnf-admin/js/reports.jsneoforum_mainpage_js?ver=0.0.1neoforum_forums_js?ver=0.0.1neoforum_trash_js?ver=0.0.1neoforum_users_js?ver=0.0.1neoforum_reports_js?ver=0.0.1HTML / DOM Fingerprints
ne-containerne-panelne-buttonne-bne-ine-une-dividerneoforum_doFormatneoforum_globals[neoforum]