
Phone Country Autodetect for Forminator Security & Risk Analysis
wordpress.org/plugins/phone-country-autodetect-for-forminatorAutomatically detects the user's country and pre-fills Forminator's phone field with the correct international calling code. Uses ipapi.
Is Phone Country Autodetect for Forminator Safe to Use in 2026?
Generally Safe
Score 100/100Phone Country Autodetect for Forminator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "phone-country-autodetect-for-forminator" plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code demonstrates good development practices with 100% of SQL queries using prepared statements and all identified outputs being properly escaped. There are no identified dangerous functions or file operations, and the taint analysis shows no unsanitized paths.
However, there are a few areas that warrant attention. The presence of an external HTTP request without further context could be a potential vector for issues if not handled securely. While there are no recorded past vulnerabilities, this does not guarantee future security. The complete absence of nonce checks and capability checks across the entire plugin is a notable weakness. While the static analysis reported zero entry points, this might be a limitation of the analysis itself or indicate a plugin that is purely a frontend enhancement. If there are any hidden or dynamically generated entry points not captured, the lack of these fundamental security checks could expose the site to risks.
In conclusion, the plugin appears to be developed with security in mind, as evidenced by its clean code signals and lack of historical vulnerabilities. The limited attack surface is a significant strength. The primary concerns stem from the external HTTP request and the absence of nonce and capability checks, which are fundamental security mechanisms in WordPress. Future development should consider implementing these checks to further harden the plugin.
Key Concerns
- External HTTP request
- No nonce checks
- No capability checks
Phone Country Autodetect for Forminator Security Vulnerabilities
Phone Country Autodetect for Forminator Code Analysis
Output Escaping
Phone Country Autodetect for Forminator Attack Surface
WordPress Hooks 3
Maintenance & Trust
Phone Country Autodetect for Forminator Maintenance & Trust
Maintenance Signals
Community Trust
Phone Country Autodetect for Forminator Alternatives
Country Code For Elementor Form Telephone Field
country-code-field-for-elementor-form
Add a country code dropdown with flags to Elementor form phone field for valid international numbers. Also works with Hello Plus form widget.
Country & Phone Field Contact Form 7
country-phone-field-contact-form-7
Add country drop down with flags and phone number with country phone extension fields in contact form 7.
Contact Form 7 – Phone mask field
cf7-phone-mask-field
This plugin adds a new field in which you can set the phone number mask or other to Contact Form 7.
International Telephone Input for Contact Form 7
international-telephone-input-for-contact-form-7
Addon for Contact Form 7 that creates a new type of input for entering and validating international telephone numbers. It adds a flag dropdown, detect …
Smart phone field for Gravity Forms
smart-phone-field-for-gravity-forms
A simple and nice plugin to get auto country flag from user ip address on gravity form phone field.
Phone Country Autodetect for Forminator Developer Profile
1 plugin · 20 total installs
How We Detect Phone Country Autodetect for Forminator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.