
Simpul Forms by Esotech Security & Risk Analysis
wordpress.org/plugins/simpul-forms-by-esotechUnder "Settings" enables "Forms" panel to customize forms to use with a shortcode. Enables "Email" panel to config SMTP …
Is Simpul Forms by Esotech Safe to Use in 2026?
Generally Safe
Score 85/100Simpul Forms by Esotech has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simpul-forms-by-esotech" plugin version 1.03 presents a mixed security posture. On the positive side, it demonstrates good practices regarding database interactions, with all SQL queries utilizing prepared statements and no known vulnerabilities (CVEs) recorded. The absence of external HTTP requests and file operations also reduces its attack surface. However, significant concerns arise from the code analysis, particularly the complete lack of output escaping. With 14 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts through user-controlled input that is then rendered on the page. Additionally, the absence of nonce checks and capability checks, while not directly leading to a deduction based on the provided data (as there are no AJAX handlers or REST API routes without permission callbacks), highlights a potential for future vulnerabilities if such entry points are introduced without proper security measures. The taint analysis showing flows with unsanitized paths is concerning, even without critical or high severity, as it suggests input is not being properly validated or cleaned before use, potentially contributing to XSS or other injection issues.
Key Concerns
- No output escaping
- Unsanitized paths in taint flows
- No nonce checks
- No capability checks
Simpul Forms by Esotech Security Vulnerabilities
Simpul Forms by Esotech Code Analysis
Output Escaping
Data Flow Analysis
Simpul Forms by Esotech Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Simpul Forms by Esotech Maintenance & Trust
Maintenance Signals
Community Trust
Simpul Forms by Esotech Alternatives
F13 Email
f13-email
Configure SMTP email, dynamic contact form builder and email logs - All in one plugin!
WP Mail SMTP by WPForms – The Most Popular SMTP and Email Log Plugin
wp-mail-smtp
Make email delivery easy for WordPress. Connect with SMTP, Gmail, Outlook, SendGrid, Mailgun, SES, Zoho, + more. Rated #1 WordPress SMTP Email plugin.
Easy WP SMTP – WordPress SMTP and Email Logs: Gmail, Office 365, Outlook, Custom SMTP, and more
easy-wp-smtp
Make SMTP email sending and delivery easy. Configure Gmail, Outlook, Brevo, SendGrid, Mailgun, SendLayer or connect to any SMTP server.
Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App
post-smtp
Improve WordPress email deliverability. Connect Gmail SMTP, Microsoft 365, Brevo, SendGrid, Mailgun, Zoho, Amazon SES, etc. #1 WordPress SMTP Plugin.
WP Mail Logging
wp-mail-logging
Log, view, and resend all emails sent from your WordPress site. Great for resolving email sending issues or keeping a copy for auditing.
Simpul Forms by Esotech Developer Profile
3 plugins · 30 total installs
How We Detect Simpul Forms by Esotech
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
wpms_options