Ninja Forms Unique Textbox Security & Risk Analysis

wordpress.org/plugins/ninja-forms-unique-textbox

Extend Ninja Forms' functionality by allowing textbox field to have unique values.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Feb 10, 2014
emailformsninjatextboxunique
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Ninja Forms Unique Textbox Safe to Use in 2026?

Generally Safe

Score 85/100

Ninja Forms Unique Textbox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The ninja-forms-unique-textbox plugin v1.0 exhibits a concerning security posture due to its single identified entry point being an unprotected AJAX handler. This creates a significant risk of unauthorized actions if an attacker can trigger this handler. While the static analysis shows no dangerous functions, file operations, or external HTTP requests, and all outputs are properly escaped, the lack of any authentication or capability checks on the AJAX handler is a critical oversight. The absence of any known vulnerabilities in its history is a positive sign, suggesting a generally secure development practice or a lack of prior scrutiny. However, this does not mitigate the immediate risk posed by the unprotected entry point. The plugin's strengths lie in its apparent clean code regarding SQL, output escaping, and lack of external dependencies. The primary weakness is the direct exposure of its functionality without any security controls.

Key Concerns

  • Unprotected AJAX handler
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Ninja Forms Unique Textbox Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Ninja Forms Unique Textbox Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared4 total queries

Output Escaping

100% escaped4 total outputs
Attack Surface
1 unprotected

Ninja Forms Unique Textbox Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_ninja_forms_delete_subcontroller.php:73
WordPress Hooks 5
actionadmin_noticescontroller.php:58
actioninitcontroller.php:61
actioninitcontroller.php:64
actionadmin_initcontroller.php:67
actionninja_forms_pre_processcontroller.php:70
Maintenance & Trust

Ninja Forms Unique Textbox Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedFeb 10, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Ninja Forms Unique Textbox Developer Profile

Fineswap

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Ninja Forms Unique Textbox

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ninja-forms-unique-textbox/css/style.css
Script Paths
/wp-content/plugins/ninja-forms-unique-textbox/js/script.js
Version Parameters
ninja-forms-unique-textbox/css/style.css?ver=ninja-forms-unique-textbox/js/script.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-unique-fielddata-unique-field-error
JS Globals
ninja_forms_unique_textbox
FAQ

Frequently Asked Questions about Ninja Forms Unique Textbox