Sliced Invoices & Formidable Forms Security & Risk Analysis

wordpress.org/plugins/sliced-invoices-formidable-forms

Create an invoice or quote request form using Formidable Forms Or Formidable Forms Pro. Each form entry then creates a quote (or an invoice) using the …

70 active installs v1.0.2 PHP + WP 4.0+ Updated May 27, 2022
formidable-formsformidable-forms-add-onformidable-forms-estimateformidable-forms-invoiceformidable-invoice
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sliced Invoices & Formidable Forms Safe to Use in 2026?

Generally Safe

Score 85/100

Sliced Invoices & Formidable Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "sliced-invoices-formidable-forms" plugin v1.0.2 exhibits a concerning security posture due to its limited attack surface being entirely unprotected. Both AJAX handlers lack authentication checks, creating a significant entry point for malicious actors. While the static analysis did not reveal dangerous functions, raw SQL queries, or critical taint flows, the high percentage of improperly escaped output (68%) suggests a risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks further exacerbates these risks, as there are no mechanisms to verify user intent or permissions for these unprotected entry points. The plugin's vulnerability history is clean, with no recorded CVEs. This could indicate either a well-developed plugin or that it hasn't been extensively targeted or audited. However, relying solely on this history is imprudent given the identified code weaknesses. The strengths lie in the absence of file operations, external HTTP requests, and the fact that a majority of SQL queries use prepared statements. Nevertheless, the unprotected AJAX handlers and poor output escaping present immediate and actionable security concerns.

Key Concerns

  • AJAX handlers without authentication
  • High percentage of unescaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Sliced Invoices & Formidable Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Sliced Invoices & Formidable Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
3 prepared
Unescaped Output
70
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

75% prepared4 total queries

Output Escaping

32% escaped103 total outputs
Attack Surface
2 unprotected

Sliced Invoices & Formidable Forms Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

noprivwp_ajax_sliced_ff_field_metasliced-invoices-formidable-forms.php:183
authwp_ajax_sliced_ff_field_metasliced-invoices-formidable-forms.php:184
WordPress Hooks 7
actioninitsliced-invoices-formidable-forms.php:69
actionadmin_noticessliced-invoices-formidable-forms.php:96
actionadmin_noticessliced-invoices-formidable-forms.php:101
actionadmin_enqueue_scriptssliced-invoices-formidable-forms.php:116
filterfrm_add_form_settings_sectionsliced-invoices-formidable-forms.php:119
actionfrm_update_formsliced-invoices-formidable-forms.php:120
actionfrm_process_entrysliced-invoices-formidable-forms.php:121
Maintenance & Trust

Sliced Invoices & Formidable Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedMay 27, 2022
PHP min version
Downloads5K

Community Trust

Rating60/100
Number of ratings2
Active installs70
Developer Profile

Sliced Invoices & Formidable Forms Developer Profile

SlicedInvoices

4 plugins · 5K total installs

66
trust score
Avg Security Score
82/100
Avg Patch Time
1040 days
View full developer profile
Detection Fingerprints

How We Detect Sliced Invoices & Formidable Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sliced-invoices-formidable-forms/assets/css/sliced-ff-style.css/wp-content/plugins/sliced-invoices-formidable-forms/assets/js/sliced-ff-custom.js
Script Paths
/wp-content/plugins/sliced-invoices-formidable-forms/assets/js/sliced-ff-custom.js
Version Parameters
sliced-invoices-formidable-forms/assets/css/sliced-ff-style.css?ver=sliced-invoices-formidable-forms/assets/js/sliced-ff-custom.js?ver=

HTML / DOM Fingerprints

Data Attributes
name="sliced_ff_type"
JS Globals
window.SIFF
FAQ

Frequently Asked Questions about Sliced Invoices & Formidable Forms