
PDF Builder for WPForms Security & Risk Analysis
wordpress.org/plugins/pdf-builder-for-wpformsThe first and only PDF drag and drop builder for WPForms.
Is PDF Builder for WPForms Safe to Use in 2026?
Generally Safe
Score 99/100PDF Builder for WPForms has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "pdf-builder-for-wpforms" plugin v1.2.141 exhibits a mixed security posture. On the positive side, it demonstrates good practices in its handling of SQL queries, with a high percentage utilizing prepared statements. The plugin also includes a reasonable number of capability checks and a single nonce check, indicating some awareness of security principles.
However, significant concerns arise from the static analysis. The plugin exposes a substantial attack surface through four AJAX handlers, all of which lack authentication checks. This is further compounded by five high-severity taint flows with unsanitized paths, suggesting potential vulnerabilities that could be exploited by an attacker. The output escaping is also a weakness, with 57% of outputs not being properly escaped, which increases the risk of cross-site scripting (XSS) vulnerabilities. The presence of bundled libraries, particularly TCPDF v1.0.004, which is an older version, could also introduce known or unknown security flaws.
The vulnerability history, though showing no currently unpatched CVEs, reveals a past with two medium-severity vulnerabilities, including Exposure of Sensitive Information and Cross-site Scripting. The recent nature of the last vulnerability (August 2024) indicates ongoing security challenges for this plugin. While the absence of unpatched critical or high vulnerabilities is a strength, the pattern of past medium-severity issues combined with the current code-level risks points to a need for significant security improvements.
Key Concerns
- 4 unprotected AJAX handlers
- 5 high severity unsanitized taint flows
- 43% of output not properly escaped
- Bundled outdated library (TCPDF v1.0.004)
- 2 medium severity CVEs in history
PDF Builder for WPForms Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
PDF Builder for WPForms <= 1.2.116 - Unauthenticated Full Path Disclosure
PDF Builder for WPForms <= 1.2.88 - Authenticated (Contributor+) Stored Cross-Site Scripting
PDF Builder for WPForms Release Timeline
PDF Builder for WPForms Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
PDF Builder for WPForms Attack Surface
AJAX Handlers 4
WordPress Hooks 16
Maintenance & Trust
PDF Builder for WPForms Maintenance & Trust
Maintenance Signals
Community Trust
PDF Builder for WPForms Alternatives
PDF Importer for WPForms
pdf-importer-for-wpform
Import a pdf, map it to a form and attaching to any email
PDF Importer for Gravity Forms
pdf-importer-for-gravity
Import a pdf, map it to a form and attaching to any email
PDF Builder for Gravity Forms
pdf-builder-for-gravity
The first and only PDF drag and drop builder for Gravity Forms.
PDF Importer for Ninja Forms
pdf-importer-for-ninjaforms-pro
Import a pdf, map it to a form and attaching to any email
PDF for WPForms + Drag and Drop Template Builder
pdf-for-wpforms
The plugin helps you create PDF for WPForms you can builder PDF template
PDF Builder for WPForms Developer Profile
19 plugins · 12K total installs
How We Detect PDF Builder for WPForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pdf-builder-for-wpforms/js/dist/DeactivationDialog_bundle.jshttps://pdfbuilder.rednao.com/HTML / DOM Fingerprints
Looks like you already have a version of the plugin installed (perhaps the free version)? please deactivate/delete it before activating this version RNPDFBuilder