
WordForm Security & Risk Analysis
wordpress.org/plugins/wordformWordForm – A powerful yet user-friendly drag-and-drop form builder for WordPress websites. Effortlessly create custom forms with advanced field option …
Is WordForm Safe to Use in 2026?
Generally Safe
Score 100/100WordForm has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wordform plugin v2.0.2 demonstrates a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history for this plugin is a significant positive indicator. The code analysis shows a commendable commitment to security best practices, with 100% of SQL queries using prepared statements and an impressive 95% of outputs being properly escaped. Furthermore, all identified entry points (AJAX handlers, REST API routes, and shortcodes) appear to have proper authentication and permission checks, indicating a well-secured attack surface. The plugin also implements a good number of nonce and capability checks relative to its entry points.
However, a few areas warrant attention. While the attack surface isn't explicitly "unprotected," the presence of 23 AJAX handlers, even with checks, represents a substantial interaction surface that could be a target for brute-force or complex exploit chains if weaknesses exist within the authorization logic. The single external HTTP request, while not inherently a vulnerability, is a potential point of failure or a vector for supply chain attacks if the external resource is compromised. The bundled DataTables library, while common, should be regularly reviewed for its own security status to mitigate risks associated with outdated dependencies. Overall, wordform v2.0.2 appears robust, but continuous vigilance on its dependencies and the complexity of its AJAX handlers is advisable.
Key Concerns
- Bundled library (DataTables) requires monitoring
- External HTTP request is a potential risk
WordForm Security Vulnerabilities
WordForm Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
WordForm Attack Surface
AJAX Handlers 23
REST API Routes 2
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
WordForm Maintenance & Trust
Maintenance Signals
Community Trust
WordForm Alternatives
HT Contact Form – Drag & Drop Form Builder for WordPress
ht-contactform
The easiest drag & drop form builder for WordPress. Create contact forms, surveys, and lead capture forms in minutes with 38+ fields and 21+ integ …
reCaptcha Add-On for FormCraft
formcraft-recaptcha
Add reCaptcha to your FormCraft forms.
Hash Form – Drag & Drop Form Builder
hash-form
Create any kind of forms effortlessly with Hash Form – the ultimate drag & drop form builder plugin for WordPress.
VPSUForm – Drag & Drop Contact Form Builder with Email Automation
v-form
A lightweight drag-and-drop WordPress form builder with email automation, conditional logic, spam protection, and full lead management.
AFB – Auto Form Builder – Drag & Drop Form Creator
auto-form-builder
Auto Form Builder is the easiest drag-and-drop form builder for WordPress. Create contact forms, surveys, and multi-step forms in minutes.
WordForm Developer Profile
2 plugins · 20 total installs
How We Detect WordForm
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wordform/assets/js/frontend.js/wp-content/plugins/wordform/assets/js/backend.js/wp-content/plugins/wordform/assets/css/frontend.css/wp-content/plugins/wordform/assets/css/backend.css/wp-content/plugins/wordform/assets/js/frontend.js/wp-content/plugins/wordform/assets/js/backend.js/wp-content/plugins/wordform/assets/js/wordform-block-editor.js/wp-content/plugins/wordform/assets/js/frontend.js/wp-content/plugins/wordform/assets/js/backend.jswordform/assets/js/frontend.js?ver=wordform/assets/js/backend.js?ver=wordform/assets/css/frontend.css?ver=wordform/assets/css/backend.css?ver=HTML / DOM Fingerprints
wordform-form-builderwordform-form-wrapperwordform-form-containerwordform-frontendwordform-backendwordform-form-fieldwordform-btnwordform-element-optionsdata-wordform-iddata-field-typedata-field-idwordform_frontend_ajax_objectwordform_backend_ajax_objectwordform_block_editor_ajax_object/wp-json/wordform/v1/all-form-list/wp-json/wordform/v1/render-selected-form