Vedrixa Forms – Contact Form, Registration Form & Drag-and-Drop Form Builder Security & Risk Analysis

wordpress.org/plugins/vedrixa-forms-registration-builder

Build contact and registration forms with a drag-and-drop WordPress form builder and submission manager.

0 active installs v1.0.2 PHP 7.4+ WP 5.8+ Updated Mar 11, 2026
contact-formform-builderregistration-formuser-registrationwordpress-forms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Vedrixa Forms – Contact Form, Registration Form & Drag-and-Drop Form Builder Safe to Use in 2026?

Generally Safe

Score 100/100

Vedrixa Forms – Contact Form, Registration Form & Drag-and-Drop Form Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin "vedrixa-forms-registration-builder" v1.1.0 exhibits a generally good security posture with several strengths. The extensive use of prepared statements for all SQL queries is a significant positive, mitigating the risk of SQL injection. Furthermore, the vast majority of output is properly escaped, and there are no recorded vulnerabilities, indicating a history of secure development practices. The plugin also correctly implements nonce and capability checks in a substantial number of instances.

However, there are notable areas of concern. The presence of an AJAX handler without authentication checks represents a direct attack vector. While the number of such handlers is small, its unprotected nature poses a significant risk. The taint analysis also reveals two high-severity flows, which, despite not being classified as critical, warrant immediate attention as they suggest potential for data manipulation or unauthorized access if exploited. The plugin's total entry points are low, which is positive, but the existence of even one unprotected entry point is a critical flaw.

In conclusion, while the plugin demonstrates a strong foundation in secure coding, the identified unprotected AJAX handler and high-severity taint flows are critical weaknesses that need to be addressed. The lack of historical vulnerabilities is encouraging, but the current findings necessitate a focused effort to patch these specific security holes to maintain its otherwise positive security standing.

Key Concerns

  • AJAX handler without authentication
  • High severity taint flows
Vulnerabilities
None known

Vedrixa Forms – Contact Form, Registration Form & Drag-and-Drop Form Builder Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Vedrixa Forms – Contact Form, Registration Form & Drag-and-Drop Form Builder Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Vedrixa Forms – Contact Form, Registration Form & Drag-and-Drop Form Builder Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
34 prepared
Unescaped Output
51
1422 escaped
Nonce Checks
10
Capability Checks
11
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared34 total queries

Output Escaping

97% escaped1473 total outputs
Data Flows · Security
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
render_form (includes/class-wpefb-form-renderer.php:48)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Vedrixa Forms – Contact Form, Registration Form & Drag-and-Drop Form Builder Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_wefb_save_form_structureincludes/class-registration-form-builder.php:172

Shortcodes 1

[wpefb_registration] public/class-registration-form-builder-public.php:232
WordPress Hooks 23
actionmedia_buttonsadmin/partials/form-settings-configure-email_templates.php:106
actionplugins_loadedincludes/class-registration-form-builder.php:150
actionadmin_enqueue_scriptsincludes/class-registration-form-builder.php:164
actionadmin_enqueue_scriptsincludes/class-registration-form-builder.php:165
actionadmin_menuincludes/class-registration-form-builder.php:166
actionadmin_initincludes/class-registration-form-builder.php:167
actionadmin_initincludes/class-registration-form-builder.php:168
actionadmin_initincludes/class-registration-form-builder.php:169
actionadmin_initincludes/class-registration-form-builder.php:170
actionadmin_initincludes/class-registration-form-builder.php:171
actionwp_enqueue_scriptsincludes/class-registration-form-builder.php:187
actionwp_enqueue_scriptsincludes/class-registration-form-builder.php:188
actionphpmailer_initincludes/class-registration-form-builder.php:189
filtershow_admin_barincludes/class-registration-form-builder.php:190
actioninitincludes/class-registration-form-builder.php:191
actioninitincludes/class-registration-form-builder.php:192
actionwp_body_openincludes/class-registration-form-builder.php:193
actionwp_footerincludes/class-registration-form-builder.php:194
filterregister_urlincludes/class-registration-form-builder.php:195
filterauthenticateincludes/class-registration-form-builder.php:196
filterquery_varsincludes/class-registration-form-builder.php:197
actiontemplate_redirectincludes/class-registration-form-builder.php:198
actionwpmu_new_blogvedrixa-forms-registration-builder.php:84
Maintenance & Trust

Vedrixa Forms – Contact Form, Registration Form & Drag-and-Drop Form Builder Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 11, 2026
PHP min version7.4
Downloads241

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Vedrixa Forms – Contact Form, Registration Form & Drag-and-Drop Form Builder Developer Profile

registrationformbuilder

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Vedrixa Forms – Contact Form, Registration Form & Drag-and-Drop Form Builder

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/vedrixa-forms-registration-builder/admin/css/jquery-ui.min.css/wp-content/plugins/vedrixa-forms-registration-builder/admin/css/registration-form-builder-admin.css/wp-content/plugins/vedrixa-forms-registration-builder/admin/css/admin.css/wp-content/plugins/vedrixa-forms-registration-builder/admin/css/style.css/wp-content/plugins/vedrixa-forms-registration-builder/admin/css/formbuilder.css/wp-content/plugins/vedrixa-forms-registration-builder/admin/js/registration-form-builder-admin.js/wp-content/plugins/vedrixa-forms-registration-builder/admin/js/formbuilder.js
Script Paths
https://fonts.googleapis.com/icon?family=Material+Icons
Version Parameters
vedrixa-forms-registration-builder/admin/css/jquery-ui.min.css?ver=vedrixa-forms-registration-builder/admin/css/registration-form-builder-admin.css?ver=vedrixa-forms-registration-builder/admin/css/admin.css?ver=vedrixa-forms-registration-builder/admin/css/style.css?ver=vedrixa-forms-registration-builder/admin/css/formbuilder.css?ver=vedrixa-forms-registration-builder/admin/js/registration-form-builder-admin.js?ver=vedrixa-forms-registration-builder/admin/js/formbuilder.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpefb-pro
Data Attributes
data-formbuilder
JS Globals
wpefb_admin_ajax_object
FAQ

Frequently Asked Questions about Vedrixa Forms – Contact Form, Registration Form & Drag-and-Drop Form Builder