Weavely – Build Forms in Figma Security & Risk Analysis

wordpress.org/plugins/weavely

Turn Figma designs into custom forms, effortlessly embed in WordPress. Elevate user experience with unique designs.

10 active installs v1.0.1 PHP 7.0+ WP 4.7+ Updated Mar 21, 2024
contact-formcustom-formemail-formform-builderforms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Weavely – Build Forms in Figma Safe to Use in 2026?

Generally Safe

Score 85/100

Weavely – Build Forms in Figma has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The Weavely plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, the consistent use of prepared statements for SQL queries, and the proper escaping of all output are significant strengths. Furthermore, the plugin does not appear to interact with external HTTP requests in an unsafe manner and has a minimal attack surface. The vulnerability history shows no recorded CVEs, suggesting a generally well-maintained and secure plugin over time.

However, there are areas that warrant attention. The complete absence of capability checks in the analyzed code is a concern, as it implies that any user, regardless of their WordPress role, could potentially interact with plugin functionalities. While the attack surface is small (one shortcode), the lack of explicit permission checks on this entry point could be a weakness if the shortcode performs sensitive operations. Taint analysis revealed no issues, which is positive, but this is based on a limited scope of zero flows analyzed. The presence of external HTTP requests, although not flagged as dangerous, should always be monitored for potential supply chain or SSRI vulnerabilities.

In conclusion, Weavely v1.0.1 is commendably secure in its handling of data and code execution. Its lack of historical vulnerabilities is a very positive indicator. The primary area for improvement lies in implementing capability checks to ensure proper authorization for all plugin functionalities, especially those accessible via shortcodes or other entry points. While the current lack of identified issues is encouraging, robust authorization mechanisms are a fundamental pillar of secure plugin development.

Key Concerns

  • No capability checks implemented
Vulnerabilities
None known

Weavely – Build Forms in Figma Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Weavely – Build Forms in Figma Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
28 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped28 total outputs
Attack Surface

Weavely – Build Forms in Figma Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[weavely_form] includes\shortcodes.php:5
WordPress Hooks 5
actionadmin_menuincludes\actions.php:5
actionadmin_initincludes\actions.php:6
actionadmin_post_weavely_logoutincludes\actions.php:7
actionadmin_post_weavely_update_teamincludes\actions.php:8
actionadmin_enqueue_scriptsincludes\actions.php:9
Maintenance & Trust

Weavely – Build Forms in Figma Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 21, 2024
PHP min version7.0
Downloads644

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Weavely – Build Forms in Figma Developer Profile

Weavely

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Weavely – Build Forms in Figma

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/weavely/assets/img/logo.svg/wp-content/plugins/weavely/assets/img/table-solid.svg/wp-content/plugins/weavely/assets/img/menu-icon.svg
Version Parameters
weavely-forms-styles?ver=

HTML / DOM Fingerprints

CSS Classes
weavely
Data Attributes
data-weavely-team-noncedata-weavely-team
Shortcode Output
<iframe src="https://app.weavely.ai/forms/" style="max-width: 100% !important;width:; height:" frameborder="0"></iframe>
FAQ

Frequently Asked Questions about Weavely – Build Forms in Figma