NEX-Forms ADD ON – Zapier Integration Security & Risk Analysis

wordpress.org/plugins/nex-forms-zapier-add-on

The NEX-Forms Zapier Integration Add-on enables you to seamlessly connect your form submissions to over 10,000 apps.

200 active installs v9.0 PHP + WP 4.0+ Updated Dec 17, 2025
contact-formsform-buildermulti-step-formswordpress-formszapier
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is NEX-Forms ADD ON – Zapier Integration Safe to Use in 2026?

Generally Safe

Score 100/100

NEX-Forms ADD ON – Zapier Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "nex-forms-zapier-add-on" v9.0 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any detected dangerous functions, unsanitized taint flows, or vulnerabilities in its history is commendable. The plugin correctly utilizes prepared statements for its SQL queries and ensures all output is properly escaped, significantly reducing the risk of common web vulnerabilities like SQL injection and cross-site scripting.

However, the analysis does reveal some areas for improvement. The complete lack of nonce checks and capability checks across all entry points, coupled with zero AJAX handlers and REST API routes that would typically benefit from such protections, is a notable concern. While the current attack surface appears minimal, any future expansion of functionality without implementing proper authorization mechanisms could introduce significant risks. The single external HTTP request, while not explicitly flagged as insecure, should be monitored for potential weaknesses if the external service it communicates with becomes compromised.

In conclusion, the plugin demonstrates good development practices regarding data sanitization and protection against direct code execution vulnerabilities. The zero-known CVEs and lack of historical vulnerabilities are positive indicators. The primary weakness lies in the absence of standard WordPress security checks like nonces and capability checks on potential entry points, which, although not exploited in the current version, represent a potential future attack vector should the plugin's functionality expand.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • External HTTP request without explicit validation
Vulnerabilities
None known

NEX-Forms ADD ON – Zapier Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

NEX-Forms ADD ON – Zapier Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped6 total outputs
Attack Surface

NEX-Forms ADD ON – Zapier Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_noticesnex-forms-zapier-add-on.php:65
Maintenance & Trust

NEX-Forms ADD ON – Zapier Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 17, 2025
PHP min version
Downloads450

Community Trust

Rating0/100
Number of ratings0
Active installs200
Developer Profile

NEX-Forms ADD ON – Zapier Integration Developer Profile

Basix

4 plugins · 9K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
357 days
View full developer profile
Detection Fingerprints

How We Detect NEX-Forms ADD ON – Zapier Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nex-forms-zapier-add-on/nex-forms-zapier-add-on.php

HTML / DOM Fingerprints

CSS Classes
integration_form_labelintegration_form_fieldzapier_helpform-control
Data Attributes
name="zapier_web_hook_url"placeholder="Enter your Webhook URL"class="form-control"
Shortcode Output
<div class="row"><br />&nbsp;</div><div class="row"><div class="integration_form_label">Zapier Webhook URL</div><div class="integration_form_field zero_padding">
FAQ

Frequently Asked Questions about NEX-Forms ADD ON – Zapier Integration