Tapform Security & Risk Analysis

wordpress.org/plugins/tapform

Connect and integrate your Tapform widget to your Wordpress website.

0 active installs v1.0 PHP 7.2+ WP 5.2+ Updated Jan 17, 2024
formslead-capturelead-databasesurveyswidgets
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Tapform Safe to Use in 2026?

Generally Safe

Score 85/100

Tapform has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The tapform v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points indicates a minimal attack surface, which is a significant positive. Furthermore, the fact that all SQL queries utilize prepared statements and there are no recorded vulnerabilities (CVEs) suggest a development team that is either highly security-conscious or has had no past security issues. The lack of identified dangerous functions and taint flows also contributes to a favorable assessment.

However, there are areas for concern. The plugin has a low percentage of properly escaped outputs (67%), implying that a third of its outputs are not adequately protected, which could lead to cross-site scripting (XSS) vulnerabilities if those outputs are user-controllable. The presence of file operations without explicit mention of sanitization or access controls warrants attention. Most notably, the complete absence of nonce checks and capability checks on any entry points, despite there being no identified entry points in the static analysis section, is a potential weakness. If new entry points are added in the future without these essential security measures, the plugin would be highly vulnerable. The plugin's history of zero vulnerabilities is excellent, but it must not lead to complacency, especially with the identified output escaping and lack of authorization checks.

Key Concerns

  • Only 67% of outputs properly escaped
  • Lack of nonce checks
  • Lack of capability checks
  • File operations without explicit checks mentioned
Vulnerabilities
None known

Tapform Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Tapform Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped3 total outputs
Attack Surface

Tapform Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menutapform.php:26
actionadmin_inittapform.php:48
actionwp_footertapform.php:74
actioninittapform.php:76
Maintenance & Trust

Tapform Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedJan 17, 2024
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Tapform Developer Profile

matejfromtapform

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Tapform

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://apimvp.tapform.io/api/forms/script

HTML / DOM Fingerprints

Data Attributes
form-identifier
Shortcode Output
<script title="Tapform Quiz" id="tapform-script" referrerpolicy="origin-when-cross-origin" src="https://apimvp.tapform.io/api/forms/script?form=
FAQ

Frequently Asked Questions about Tapform