WebConnex Form Management Security & Risk Analysis

wordpress.org/plugins/webconnex-form-managment

This plugin allows you to easily insert WebConnex forms into your WordPress site. A WebConnex account is required.

500 active installs v1.6.19 PHP + WP 4.1.1+ Updated Mar 15, 2021
formsgivingfuelredpodiumregistrationwebconnex
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WebConnex Form Management Safe to Use in 2026?

Generally Safe

Score 85/100

WebConnex Form Management has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The static analysis of webconnex-form-managment v1.6.19 reveals a generally positive security posture, with no detected dangerous functions, all SQL queries utilizing prepared statements, and all output being properly escaped. The absence of file operations and external HTTP requests further mitigates common attack vectors. Crucially, the analysis indicates no taint flows, meaning there are no identified pathways for unsanitized user input to reach sensitive operations, which is a strong indicator of secure coding practices.

However, a significant concern is the lack of any capability checks or nonce checks identified in the static analysis. While the attack surface appears small with only one shortcode and no unprotected AJAX handlers or REST API routes, the absence of these crucial security mechanisms on the shortcode entry point presents a potential risk. If the shortcode handles any user-provided data or performs actions that should be restricted, the lack of these checks could allow unauthorized access or actions.

The plugin's vulnerability history is also a strong positive, with zero recorded CVEs. This indicates a history of stability and likely proactive security maintenance by the developers. In conclusion, the plugin demonstrates strong adherence to secure coding principles for data handling and output, but the identified lack of authorization and nonce checks on its sole entry point is a notable weakness that requires attention.

Key Concerns

  • Missing capability checks on entry points
  • Missing nonce checks on entry points
Vulnerabilities
None known

WebConnex Form Management Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WebConnex Form Management Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped10 total outputs
Attack Surface

WebConnex Form Management Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wxform] wx-form-management.php:26
WordPress Hooks 3
actionmedia_buttons_contextwx-form-management.php:27
actionadmin_footerwx-form-management.php:28
actionadmin_enqueue_scriptswx-form-management.php:29
Maintenance & Trust

WebConnex Form Management Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 15, 2021
PHP min version
Downloads23K

Community Trust

Rating0/100
Number of ratings0
Active installs500
Developer Profile

WebConnex Form Management Developer Profile

jordancolburn

1 plugin · 500 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WebConnex Form Management

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webconnex-form-managment/wx-form-management-styles.css/wp-content/plugins/webconnex-form-managment/iframeResizer.min.js/wp-content/plugins/webconnex-form-managment/wx-form-management.js/wp-content/plugins/webconnex-form-managment/admin/css/wx-form-management-admin.css/wp-content/plugins/webconnex-form-managment/admin/js/wx-form-management-admin.js
Script Paths
/wp-content/plugins/webconnex-form-managment/iframeResizer.min.js/wp-content/plugins/webconnex-form-managment/wx-form-management.js/wp-content/plugins/webconnex-form-managment/admin/js/wx-form-management-admin.js
Version Parameters
webconnex-form-managment/wx-form-management-styles.css?ver=webconnex-form-managment/iframeResizer.min.js?ver=webconnex-form-managment/wx-form-management.js?ver=webconnex-form-managment/admin/css/wx-form-management-admin.css?ver=webconnex-form-managment/admin/js/wx-form-management-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wx-form-management-stylesholds-wc-buttonwx-buttonholds-wx-embedwx-embedwx_popup_containerwx-type-optionswx-color-picker
Data Attributes
id="insert-wxform-button"id="wx_popup_container"class="wx_popup_container"id="wx-url"id="wx-type"class="wx-type-options"+5 more
JS Globals
window.tb_show
Shortcode Output
[wxform url="[wxform url="[wxform url="
FAQ

Frequently Asked Questions about WebConnex Form Management