Smart AI Forms – AI Form Builder for WordPress Security & Risk Analysis

wordpress.org/plugins/smart-ai-forms-lite

The only WordPress form builder that generates complete forms from a plain English prompt. No API key needed. Drag, drop, or just describe it.

10 active installs v1.0.1 PHP 7.4+ WP 5.0+ Updated Feb 28, 2026
ai-form-builderai-formscontact-formdrag-and-dropform-builder
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Smart AI Forms – AI Form Builder for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

Smart AI Forms – AI Form Builder for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "smart-ai-forms-lite" v1.0.1 plugin exhibits a generally strong security posture, with an excellent track record of no known vulnerabilities and robust implementation of security best practices. The plugin demonstrates a high percentage of prepared statements for SQL queries and properly escaped output, minimizing risks associated with data manipulation and injection. The presence of numerous nonce and capability checks further strengthens its defense against common WordPress attacks. However, a significant concern arises from the substantial attack surface, particularly the 5 AJAX handlers that lack authentication checks. This presents a potential entry point for attackers to exploit functionalities that should be protected from unauthorized access.

The taint analysis, while not revealing critical or high-severity issues, did identify 5 flows with unsanitized paths. While these did not escalate to exploitable vulnerabilities in this analysis, they represent potential weaknesses that could be leveraged in conjunction with other factors or in different contexts. The vulnerability history is a clear positive, indicating a well-maintained and secure codebase to date. Despite the lack of historical vulnerabilities, the presence of unprotected AJAX endpoints remains a notable weakness that requires attention. Overall, the plugin is well-developed with good security practices in place, but the unprotected AJAX handlers introduce a specific, actionable risk that should be addressed to achieve a more secure state.

Key Concerns

  • AJAX handlers without authentication checks
  • Taint flows with unsanitized paths
Vulnerabilities
None known

Smart AI Forms – AI Form Builder for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Smart AI Forms – AI Form Builder for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
46 prepared
Unescaped Output
12
468 escaped
Nonce Checks
26
Capability Checks
29
File Operations
6
External Requests
0
Bundled Libraries
0

SQL Query Safety

88% prepared52 total queries

Output Escaping

98% escaped480 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

14 flows5 with unsanitized paths
entries_page (includes\class-admin.php:592)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Smart AI Forms – AI Form Builder for WordPress Attack Surface

Entry Points19
Unprotected5

AJAX Handlers 18

authwp_ajax_smaraifo_save_formincludes\class-ajax.php:19
authwp_ajax_smaraifo_load_formincludes\class-ajax.php:20
authwp_ajax_smaraifo_delete_formincludes\class-ajax.php:21
authwp_ajax_smaraifo_duplicate_formincludes\class-ajax.php:22
authwp_ajax_smaraifo_download_entriesincludes\class-ajax.php:23
authwp_ajax_smaraifo_delete_entryincludes\class-ajax.php:24
authwp_ajax_smaraifo_submitincludes\class-ajax.php:28
noprivwp_ajax_smaraifo_submitincludes\class-ajax.php:29
authwp_ajax_smaraifo_refresh_nonceincludes\class-ajax.php:31
noprivwp_ajax_smaraifo_refresh_nonceincludes\class-ajax.php:32
authwp_ajax_smaraifo_save_form_stylesincludes\class-field-customizer.php:14
authwp_ajax_smaraifo_save_field_stylesincludes\class-field-customizer.php:15
authwp_ajax_smaraifo_get_field_settingsincludes\class-form-builder.php:27
authwp_ajax_smaraifo_render_field_previewincludes\class-form-builder.php:28
authwp_ajax_smaraifo_duplicate_fieldincludes\class-form-builder.php:29
authwp_ajax_smaraifo_import_formincludes\class-form-builder.php:30
authwp_ajax_smaraifo_export_formincludes\class-form-builder.php:31
authwp_ajax_smaraifo_get_form_stylesincludes\class-frontend.php:1417

Shortcodes 1

[smaraifo_form] includes\class-frontend.php:13
WordPress Hooks 29
actionadmin_menuincludes\class-admin.php:14
actionsmaraifo_cleanup_exportincludes\class-ajax.php:25
actioninitincludes\class-blocks.php:14
actionenqueue_block_editor_assetsincludes\class-blocks.php:15
actionelementor/elements/categories_registeredincludes\class-elementor.php:11
actionelementor/widgets/registerincludes\class-elementor.php:14
actionelementor/widgets/widgets_registeredincludes\class-elementor.php:17
actionadmin_menuincludes\class-email.php:10
actionadmin_post_smaraifo_save_emailincludes\class-email.php:11
actionadmin_post_smaraifo_send_test_emailincludes\class-email.php:12
filterwp_mail_fromincludes\class-email.php:15
filterwp_mail_from_nameincludes\class-email.php:16
actionphpmailer_initincludes\class-email.php:19
actionadmin_menuincludes\class-field-customizer.php:10
actionadmin_enqueue_scriptsincludes\class-field-customizer.php:11
actionadmin_post_smaraifo_save_form_stylesincludes\class-field-customizer.php:18
actionadmin_post_smaraifo_save_field_stylesincludes\class-field-customizer.php:19
actionwp_footerincludes\class-frontend.php:775
actionwp_headincludes\class-frontend.php:777
actionwp_enqueue_scriptsincludes\class-frontend.php:778
actioncustomize_registerincludes\class-frontend.php:1414
actioncustomize_save_afterincludes\class-frontend.php:1415
actioncustomize_controls_enqueue_scriptsincludes\class-frontend.php:1416
actionadmin_menuincludes\class-notifications.php:6
actionadmin_post_smaraifo_save_notificationsincludes\class-notifications.php:7
actioninitsmart-ai-forms-lite.php:71
actionwp_enqueue_scriptssmart-ai-forms-lite.php:123
actionadmin_enqueue_scriptssmart-ai-forms-lite.php:124
actionwp_footersmart-ai-forms-lite.php:125

Scheduled Events 2

smaraifo_cleanup_export
smaraifo_cleanup_export
Maintenance & Trust

Smart AI Forms – AI Form Builder for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 28, 2026
PHP min version7.4
Downloads228

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Smart AI Forms – AI Form Builder for WordPress Developer Profile

cpimediabhushan

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smart AI Forms – AI Form Builder for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/smart-ai-forms-lite/assets/js/frontend.js/wp-content/plugins/smart-ai-forms-lite/assets/css/frontend.css/wp-content/plugins/smart-ai-forms-lite/assets/js/admin.js/wp-content/plugins/smart-ai-forms-lite/assets/css/admin.css/wp-content/plugins/smart-ai-forms-lite/assets/vendor/chart.min.js
Script Paths
/wp-content/plugins/smart-ai-forms-lite/assets/js/frontend.js/wp-content/plugins/smart-ai-forms-lite/assets/js/admin.js/wp-content/plugins/smart-ai-forms-lite/assets/vendor/chart.min.js
Version Parameters
smart-ai-forms-lite/assets/js/frontend.js?ver=smart-ai-forms-lite/assets/css/frontend.css?ver=smart-ai-forms-lite/assets/js/admin.js?ver=smart-ai-forms-lite/assets/css/admin.css?ver=smart-ai-forms-lite/assets/vendor/chart.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
smaraifo_ajaxsmaraifo_adminsmaraifoCopyToClipboard
JS Globals
smaraifo_ajaxsmaraifo_adminsmaraifoCopyToClipboard
FAQ

Frequently Asked Questions about Smart AI Forms – AI Form Builder for WordPress