
Contact Form & SMTP Plugin for WordPress by PirateForms Security & Risk Analysis
wordpress.org/plugins/pirate-formsA simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
Is Contact Form & SMTP Plugin for WordPress by PirateForms Safe to Use in 2026?
Generally Safe
Score 87/100Contact Form & SMTP Plugin for WordPress by PirateForms has a strong security track record. Known vulnerabilities have been patched promptly.
The pirate-forms plugin v2.6.1 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns remain regarding its attack surface. The presence of two AJAX handlers without authentication checks creates a direct entry point for unauthenticated attackers to interact with the plugin's backend logic. This is particularly worrisome given the plugin's history of vulnerabilities, including critical and high severity Cross-site Scripting (XSS) and Code Injection flaws. Although no currently unpatched CVEs are listed, the recurring nature of these severe vulnerability types in the past suggests a pattern of insecure input handling that could be present in this version. The plugin's strengths lie in its secure data handling for SQL and output, but the unprotected AJAX endpoints coupled with past vulnerability trends elevate the risk profile.
Key Concerns
- Unprotected AJAX handlers
- History of High severity vulnerabilities
- History of Medium severity vulnerabilities
- Unsanitized input risk due to past XSS/Code Injection
Contact Form & SMTP Plugin for WordPress by PirateForms Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Contact Form & SMTP Plugin for WordPress by PirateForms <= 2.5.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Contact Form & SMTP Plugin for WordPress by PirateForms <= 2.5.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Contact Form & SMTP Plugin for WordPress by PirateForms <= 2.6.0 - Unauthenticated Arbitrary Shortcode Execution
Contact Form & SMTP Plugin by PirateForms <= 2.5.1 - Unauthenticated HTML injection
Contact Form & SMTP Plugin for WordPress by PirateForms Code Analysis
Output Escaping
Data Flow Analysis
Contact Form & SMTP Plugin for WordPress by PirateForms Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 32
Maintenance & Trust
Contact Form & SMTP Plugin for WordPress by PirateForms Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form & SMTP Plugin for WordPress by PirateForms Alternatives
MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder
mailchimp-subscribe-sm
MailChimp Subscribe Form allows you to create Beautiful Professional looking Subscribe Forms, Popups, bars & full page optins easily in less than …
Simon's Simple Contact Form
simons-simple-contact-form
A lightweight WordPress contact form plugin with 18 themes, SMTP support, Google reCAPTCHA or internal captcha, and instant theme switching.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
forminator
Best WordPress form builder plugin. Create contact forms, payment forms & order forms with 1000+ integrations.
Contact Form & SMTP Plugin for WordPress by PirateForms Developer Profile
94 plugins · 23.5M total installs
How We Detect Contact Form & SMTP Plugin for WordPress by PirateForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pirate-forms/admin/css/wp-admin.css/wp-content/plugins/pirate-forms/admin/js/scripts-admin.js/wp-content/plugins/pirate-forms/admin/css/farewell.css/wp-content/plugins/pirate-forms/admin/css/migration.css/wp-content/plugins/pirate-forms/admin/js/migration.js/wp-content/plugins/pirate-forms/admin/css/wp-admin.css?ver=/wp-content/plugins/pirate-forms/admin/js/scripts-admin.js?ver=/wp-content/plugins/pirate-forms/admin/css/farewell.css?ver=/wp-content/plugins/pirate-forms/admin/css/migration.css?ver=/wp-content/plugins/pirate-forms/admin/js/migration.js?ver=HTML / DOM Fingerprints
pirateforms-admin-wrappirateforms-admin-navpf-tooltippf-forms-titlepf-forms-listpf-forms-editpf-forms-deletepf-forms-duplicate+7 more<!-- Plugin Pirate Forms --><!-- Plugin URI: http://themeisle.com/plugins/pirate-forms/ --><!-- Description: Easily creates a nice looking, simple contact form on your WP site. --><!-- Author: WPForms -->+17 moredata-pf-iddata-pf-slugdata-pf-redirectdata-pf-noncedata-pf-actiondata-pf-form-title+2 morepirateforms_scripts_admincwp_top_ajaxload/wp-json/pirateforms/v1/forms