
PDF Importer for WPForms Security & Risk Analysis
wordpress.org/plugins/pdf-importer-for-wpformImport a pdf, map it to a form and attaching to any email
Is PDF Importer for WPForms Safe to Use in 2026?
Generally Safe
Score 100/100PDF Importer for WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pdf-importer-for-wpform" plugin v1.3.80 exhibits a mixed security posture. While it demonstrates good practices by predominantly using prepared statements for SQL queries and having a clean vulnerability history with no known CVEs, significant concerns arise from its attack surface and code analysis. The presence of one AJAX handler without authentication checks presents a direct pathway for potential unauthorized actions. Furthermore, the use of the `unserialize` function, especially when combined with unsanitized input, poses a critical risk of remote code execution if an attacker can control the serialized data. The taint analysis, revealing two flows with unsanitized paths, further emphasizes the potential for these vulnerabilities to be exploited, even though no critical or high severity issues were flagged directly by the taint analysis itself. The lack of nonce and capability checks on the identified AJAX endpoint exacerbates this risk. Overall, the plugin has a concerning reliance on potentially insecure code practices for its sole unprotected entry point, despite an otherwise clean security track record.
Key Concerns
- Unprotected AJAX handler
- Dangerous function: unserialize
- Taint flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
- Output escaping is only 56% proper
PDF Importer for WPForms Security Vulnerabilities
PDF Importer for WPForms Release Timeline
PDF Importer for WPForms Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
PDF Importer for WPForms Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
PDF Importer for WPForms Maintenance & Trust
Maintenance Signals
Community Trust
PDF Importer for WPForms Alternatives
PDF Builder for WPForms
pdf-builder-for-wpforms
The first and only PDF drag and drop builder for WPForms.
PDF Importer for Gravity Forms
pdf-importer-for-gravity
Import a pdf, map it to a form and attaching to any email
PDF Builder for Gravity Forms
pdf-builder-for-gravity
The first and only PDF drag and drop builder for Gravity Forms.
PDF Importer for Ninja Forms
pdf-importer-for-ninjaforms-pro
Import a pdf, map it to a form and attaching to any email
PDF for WPForms + Drag and Drop Template Builder
pdf-for-wpforms
The plugin helps you create PDF for WPForms you can builder PDF template
PDF Importer for WPForms Developer Profile
19 plugins · 12K total installs
How We Detect PDF Importer for WPForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pdf-importer-for-wpform/pdfimporter.css/wp-content/plugins/pdf-importer-for-wpform/pdfimporter.js/wp-content/plugins/pdf-importer-for-wpform/api/pdfimporterapi.js/wp-content/plugins/pdf-importer-for-wpform/core/admin/js/pluginbase.js/wp-content/plugins/pdf-importer-for-wpform/core/admin/js/adminpage.js/wp-content/plugins/pdf-importer-for-wpform/core/admin/js/wpform-integration.js/wp-content/plugins/pdf-importer-for-wpform/core/admin/js/pdf-form-generator.js/wp-content/plugins/pdf-importer-for-wpform/core/admin/js/pdf-form-builder.js+2 more/wp-content/plugins/pdf-importer-for-wpform/pdfimporter.js/wp-content/plugins/pdf-importer-for-wpform/api/pdfimporterapi.js/wp-content/plugins/pdf-importer-for-wpform/core/admin/js/pluginbase.js/wp-content/plugins/pdf-importer-for-wpform/core/admin/js/adminpage.js/wp-content/plugins/pdf-importer-for-wpform/core/admin/js/wpform-integration.js/wp-content/plugins/pdf-importer-for-wpform/core/admin/js/pdf-form-generator.js+3 morepdf-importer-for-wpform/pdfimporter.css?ver=pdf-importer-for-wpform/pdfimporter.js?ver=pdf-importer-for-wpform/api/pdfimporterapi.js?ver=pdf-importer-for-wpform/core/admin/js/pluginbase.js?ver=pdf-importer-for-wpform/core/admin/js/adminpage.js?ver=pdf-importer-for-wpform/core/admin/js/wpform-integration.js?ver=pdf-importer-for-wpform/core/admin/js/pdf-form-generator.js?ver=pdf-importer-for-wpform/core/admin/js/pdf-form-builder.js?ver=pdf-importer-for-wpform/core/admin/js/pdf-form-editor.js?ver=pdf-importer-for-wpform/core/admin/js/pdf-importer-entry-viewer.js?ver=HTML / DOM Fingerprints
pdf-form-generator-containerdata-pdfimporterapidata-rnpdfimporterRNPDFImporter