Visual Form Builder – Custom Validation Messages Security & Risk Analysis

wordpress.org/plugins/vfb-custom-validation-messages

Customize the default jQuery validation messages for all Visual Form Builder or Visual Form Builder Pro forms.

200 active installs v1.2 PHP + WP 3.5.1+ Updated Jan 28, 2014
contact-formform-builderformsjquery-validation
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Visual Form Builder – Custom Validation Messages Safe to Use in 2026?

Generally Safe

Score 85/100

Visual Form Builder – Custom Validation Messages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The vfb-custom-validation-messages v1.2 plugin exhibits a strong security posture based on the provided static analysis. It reports zero AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces its attack surface. Furthermore, the absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is highly commendable. The presence of a nonce check and 100% prepared statement usage for SQL queries are positive indicators of secure coding practices.

However, a notable concern is the low percentage (8%) of properly escaped output. With 24 total outputs analyzed, this suggests that a significant number of them could be vulnerable to cross-site scripting (XSS) attacks if the data being output originates from user input or an untrusted source. While no critical or high-severity taint flows were identified, the potential for XSS due to insufficient output escaping is a real risk that warrants attention.

The plugin's vulnerability history is entirely clean, with zero recorded CVEs. This, combined with the overall lack of identified critical security flaws in the static analysis, suggests that the developers have generally maintained a good security standard. Despite the identified output escaping issue, the plugin's strengths in attack surface reduction and secure database interaction make its overall security profile lean towards good, provided the output escaping issue is addressed.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Visual Form Builder – Custom Validation Messages Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Visual Form Builder – Custom Validation Messages Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

8% escaped24 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
save (vfb-custom-validation-messages.php:132)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Visual Form Builder – Custom Validation Messages Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuvfb-custom-validation-messages.php:65
actionadmin_initvfb-custom-validation-messages.php:68
actionplugins_loadedvfb-custom-validation-messages.php:71
actionadmin_initvfb-custom-validation-messages.php:74
actionadmin_noticesvfb-custom-validation-messages.php:77
actionwp_footervfb-custom-validation-messages.php:80
Maintenance & Trust

Visual Form Builder – Custom Validation Messages Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedJan 28, 2014
PHP min version
Downloads10K

Community Trust

Rating80/100
Number of ratings4
Active installs200
Developer Profile

Visual Form Builder – Custom Validation Messages Developer Profile

Matthew Muro

4 plugins · 23K total installs

68
trust score
Avg Security Score
84/100
Avg Patch Time
1663 days
View full developer profile
Detection Fingerprints

How We Detect Visual Form Builder – Custom Validation Messages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Visual Form Builder – Custom Validation Messages