
Webhookify – Send Form Submissions to Webhooks Security & Risk Analysis
wordpress.org/plugins/webhookify-send-form-submissions-to-webhooksSend form submissions from Contact Form 7, WPForms, Gravity Forms, Elementor Forms, and Formidable Forms to any webhook URL instantly.
Is Webhookify – Send Form Submissions to Webhooks Safe to Use in 2026?
Generally Safe
Score 100/100Webhookify – Send Form Submissions to Webhooks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "webhookify-send-form-submissions-to-webhooks" plugin version 1.0.0 exhibits a strong security posture based on the provided static analysis. It successfully avoids dangerous functions, utilizes prepared statements for all SQL queries, and implements proper output escaping for the vast majority of its outputs. Furthermore, the presence of a nonce check and a capability check on its single AJAX handler indicates a good understanding of core WordPress security practices. The absence of any reported vulnerabilities in its history further bolsters this assessment, suggesting a mature and well-maintained codebase.
While the plugin demonstrates excellent security hygiene, the analysis does highlight two external HTTP requests. Without further context from taint analysis, it's impossible to definitively assess the risk associated with these requests. However, any external interaction inherently carries a potential for vulnerability if not handled with extreme care, such as proper input validation and sanitization of data being sent externally, and robust validation of data received from external sources. The lack of any taint flows reported is a positive indicator, suggesting that even if external requests are made, they are not currently exhibiting critical or high-severity unsanitized data flows.
In conclusion, this plugin appears to be very secure, with a minimal attack surface and a clear commitment to secure coding practices. The only area that warrants a cautious eye is the nature of its external HTTP requests, which, while not currently flagged by taint analysis, is a standard consideration for any plugin interacting with external services.
Key Concerns
- External HTTP requests present potential risk
Webhookify – Send Form Submissions to Webhooks Security Vulnerabilities
Webhookify – Send Form Submissions to Webhooks Code Analysis
Output Escaping
Webhookify – Send Form Submissions to Webhooks Attack Surface
AJAX Handlers 1
WordPress Hooks 9
Maintenance & Trust
Webhookify – Send Form Submissions to Webhooks Maintenance & Trust
Maintenance Signals
Community Trust
Webhookify – Send Form Submissions to Webhooks Alternatives
Hooksure
hooksure
Hooksure allows you to map SureForms, form submissions to webhooks dynamically within your WordPress admin dashboard without needing the pro plugin.
Lazy Webhook Relay for WPForms
lazy-wpforms-webhook-relay
Are you a lazy developer? This plugin sends every WPForms submission to an endpoint in the background. Make that data someone else's problem!
Zoho Flow – Integrate 100+ plugins with 1000+ business apps, no-code workflow automation
zoho-flow
Integrate your WordPress plugins with your business applications and automate workflows between them. A single platform for all your integrations.
Retrigger Notifications Gravity Forms
retrigger-notifications-gravity-forms
Resend Gravity Forms entry data to Zapier and Webhook feeds with one click -- no need to resubmit the form.
Webhook for Bricks Forms
webhook-for-bricks-forms
Adds form ID and webhook URL pairs to trigger specific webhooks on Bricks form submissions, with debug options.
Webhookify – Send Form Submissions to Webhooks Developer Profile
1 plugin · 90 total installs
How We Detect Webhookify – Send Form Submissions to Webhooks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webhookify-send-form-submissions-to-webhooks/icon.pngHTML / DOM Fingerprints
wp-menu-imagename="webhookify_settings[webhook_url]"name="webhookify_settings[enabled]"