
Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls Security & Risk Analysis
wordpress.org/plugins/powr-packThe best 60 plugins for WP. Easy contact form plugin, social feed, popup, countdown, and more.
Is Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls Safe to Use in 2026?
Generally Safe
Score 91/100Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "powr-pack" v2.2.2 exhibits a mixed security posture. On the positive side, the static analysis reveals a small attack surface with no identified AJAX handlers or REST API routes lacking authentication, and all SQL queries are properly prepared. There are also no critical or high severity taint flows identified, and no file operations or external HTTP requests are present, which generally reduces the potential for certain types of attacks.
However, several areas raise concerns. The significant proportion of improperly escaped output (75%) is a major weakness and a primary indicator of potential Cross-Site Scripting (XSS) vulnerabilities. This is further corroborated by the vulnerability history, which shows two medium severity CVEs primarily related to XSS. The absence of nonce checks on the single identified shortcode, while not explicitly flagged as unprotected by the attack surface analysis, warrants attention as it could potentially be exploited if the shortcode's functionality is sensitive.
In conclusion, while the plugin avoids some common pitfalls like raw SQL queries and a large attack surface, the prevalence of unescaped output and the history of XSS vulnerabilities are significant risks. The lack of explicit nonce checks on the shortcode adds another layer of potential concern. While the plugin does not currently have unpatched CVEs, the consistent pattern of XSS issues suggests a need for more robust output sanitization practices.
Key Concerns
- Significant unescaped output detected (75%)
- History of medium severity XSS vulnerabilities
- Bundled library TinyMCE (potential outdatedness)
- No nonce checks on identified shortcode
Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Powr Pack <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
POWR <= 2.1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls Release Timeline
Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls Code Analysis
Bundled Libraries
Output Escaping
Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls Attack Surface
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls Maintenance & Trust
Maintenance Signals
Community Trust
Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls Alternatives
Forminator Forms – Contact Form, Payment Form & Custom Form Builder
forminator
Best WordPress form builder plugin. Create contact forms, payment forms & order forms with 1000+ integrations.
SureForms – Contact Form, Payment Form & Other Custom Form Builder
sureforms
The most beginner-friendly AI Form Builder for WordPress. Create contact, payment, quiz & custom forms with advanced features in minutes.
Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform
embed-form
Create and embed secure online forms in WordPress using Jotform’s drag-and-drop builder, with PCI and HIPAA compliance and full data-security support.
Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder
gutena-forms
WordPress form builder to create lightweight contact forms, survey forms, feedback forms, booking forms, etc., right inside the block editor.
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms
happyforms
Best WordPress contact form, newsletter form and payment form builder without the sucky stuff — lost emails, pesky spam, leaky privacy and outsourced …
Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls Developer Profile
5 plugins · 1K total installs
How We Detect Custom Form Builder, Contact Forms, Payment Forms, Surveys, Polls
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/powr-pack/dist/blocks.style.build.css/wp-content/plugins/powr-pack/dist/blocks.build.js/wp-content/plugins/powr-pack/dist/blocks.editor.build.css//www.powr.io/powr.js?external-type=wordpress//localhost:3000/powr_local.js?external-type=wordpressHTML / DOM Fingerprints
powr-widget-container<!-- POWr Pack widget --><!-- This is an integration of a POWr.io widget. -->data-powr-widget-iddata-powr-widget-typewindow.powr_token[powr_pack]