
RAO Forms Security & Risk Analysis
wordpress.org/plugins/rao-formsManage Website or APP form submissions at one place i.e. RAO Form Builder.
Is RAO Forms Safe to Use in 2026?
Generally Safe
Score 100/100RAO Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rao-forms" plugin version 1.0.0 exhibits a concerning security posture primarily due to its unprotected entry points and lack of robust authorization checks. While the plugin does not contain overtly dangerous functions or report known past vulnerabilities, the static analysis reveals significant weaknesses. Specifically, all four identified AJAX handlers are without authentication checks, presenting a direct attack vector. Furthermore, all analyzed taint flows resulted in unsanitized paths, with two classified as high severity, indicating potential for data manipulation or leakage through these handlers. The complete absence of capability checks for these entry points exacerbates the risk, as any authenticated user, regardless of their role, could potentially exploit these flaws. The high percentage of properly escaped output and the absence of file operations are positive signs, suggesting some attention to secure coding practices in those areas. However, the lack of prepared statements for all SQL queries, while not ideal, is less critical than the unprotected AJAX endpoints given the current findings. The bundled outdated Select2 library is a minor concern but warrants attention. In conclusion, while the plugin's vulnerability history is clean, the current static analysis highlights critical security gaps that need immediate attention to mitigate potential risks.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- No capability checks on AJAX handlers
- Raw SQL queries without prepared statements
- Bundled outdated Select2 library
RAO Forms Security Vulnerabilities
RAO Forms Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
RAO Forms Attack Surface
AJAX Handlers 4
WordPress Hooks 23
Maintenance & Trust
RAO Forms Maintenance & Trust
Maintenance Signals
Community Trust
RAO Forms Alternatives
Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-hubspot
Send Contact Form 7, WPForms, Elementor, Ninja Forms, WPforms, Elementor, Ninja Forms, Contact Form Entries Plugin and many other contact form submiss …
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin
cf7-zoho
Send Contact Form 7, WPforms, Elementor, Formidable, Ninja Forms and many other contact form submissions to zoho CRM and Bigin.
Autopreenchimento de endereço em formulários
cf7-cep-autofill
Preenchimento automático de campos de endereço baseado no CEP informado.
Integration for Google Sheets and Contact Form 7, WPForms, Elementor, Ninja Forms
integration-for-contact-form-7-and-google-sheets
Send Contact Form 7, WPForms, Elementor, Ninja Forms, Contact Form Entries Plugin and many other contact form submissions to Google Sheets.
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms
integration-for-contact-form-7-and-pipedrive
Send Contact Form 7, WPForms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to Pipedrive.
RAO Forms Developer Profile
3 plugins · 110 total installs
How We Detect RAO Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rao-forms/assets/select2/select2.css/wp-content/plugins/rao-forms/assets/select2/select2.min.js/wp-content/plugins/rao-forms/admin/css/rfip-admin.css/wp-content/plugins/rao-forms/admin/js/rfip-admin.js/wp-content/plugins/rao-forms/admin/js/rfip-connect.js/wp-content/plugins/rao-forms/admin/js/rfip-general.jswp-content/plugins/rao-forms/assets/select2/select2.min.jswp-content/plugins/rao-forms/admin/js/rfip-admin.jswp-content/plugins/rao-forms/admin/js/rfip-connect.jswp-content/plugins/rao-forms/admin/js/rfip-general.jsrao-forms/assets/select2/select2.css?ver=rao-forms/assets/select2/select2.min.js?ver=rao-forms/admin/css/rfip-admin.css?ver=rao-forms/admin/js/rfip-admin.js?ver=rao-forms/admin/js/rfip-connect.js?ver=rao-forms/admin/js/rfip-general.js?ver=HTML / DOM Fingerprints
data-url="https://app.raoforms.com/"window.raoforms