Webhookify – Send Form Submissions to Webhooks Security & Risk Analysis

wordpress.org/plugins/webhookify-send-form-submissions-to-webhooks

Send form submissions from Contact Form 7, WPForms, Gravity Forms, Elementor Forms, and Formidable Forms to any webhook URL instantly.

90 active installs v1.0.0 PHP 7.2+ WP 5.0+ Updated Nov 12, 2025
automationformsintegrationnotificationswebhook
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Webhookify – Send Form Submissions to Webhooks Safe to Use in 2026?

Generally Safe

Score 100/100

Webhookify – Send Form Submissions to Webhooks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "webhookify-send-form-submissions-to-webhooks" plugin version 1.0.0 exhibits a strong security posture based on the provided static analysis. It successfully avoids dangerous functions, utilizes prepared statements for all SQL queries, and implements proper output escaping for the vast majority of its outputs. Furthermore, the presence of a nonce check and a capability check on its single AJAX handler indicates a good understanding of core WordPress security practices. The absence of any reported vulnerabilities in its history further bolsters this assessment, suggesting a mature and well-maintained codebase.

While the plugin demonstrates excellent security hygiene, the analysis does highlight two external HTTP requests. Without further context from taint analysis, it's impossible to definitively assess the risk associated with these requests. However, any external interaction inherently carries a potential for vulnerability if not handled with extreme care, such as proper input validation and sanitization of data being sent externally, and robust validation of data received from external sources. The lack of any taint flows reported is a positive indicator, suggesting that even if external requests are made, they are not currently exhibiting critical or high-severity unsanitized data flows.

In conclusion, this plugin appears to be very secure, with a minimal attack surface and a clear commitment to secure coding practices. The only area that warrants a cautious eye is the nature of its external HTTP requests, which, while not currently flagged by taint analysis, is a standard consideration for any plugin interacting with external services.

Key Concerns

  • External HTTP requests present potential risk
Vulnerabilities
None known

Webhookify – Send Form Submissions to Webhooks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Webhookify – Send Form Submissions to Webhooks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
14 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

93% escaped15 total outputs
Attack Surface

Webhookify – Send Form Submissions to Webhooks Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_webhookify_testwebhookify.php:449
WordPress Hooks 9
actionadmin_menuwebhookify.php:24
actionadmin_initwebhookify.php:25
actionadmin_enqueue_scriptswebhookify.php:26
actionwpcf7_before_send_mailwebhookify.php:28
actionwpforms_process_completewebhookify.php:30
actiongform_after_submissionwebhookify.php:32
actionelementor_pro/forms/new_recordwebhookify.php:34
actionfrm_after_create_entrywebhookify.php:36
actioncomment_postwebhookify.php:38
Maintenance & Trust

Webhookify – Send Form Submissions to Webhooks Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 12, 2025
PHP min version7.2
Downloads356

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

Webhookify – Send Form Submissions to Webhooks Developer Profile

Bibek Acharya

1 plugin · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Webhookify – Send Form Submissions to Webhooks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webhookify-send-form-submissions-to-webhooks/icon.png

HTML / DOM Fingerprints

CSS Classes
wp-menu-image
Data Attributes
name="webhookify_settings[webhook_url]"name="webhookify_settings[enabled]"
FAQ

Frequently Asked Questions about Webhookify – Send Form Submissions to Webhooks