
WP-Stateless – WPForms Addon Security & Risk Analysis
wordpress.org/plugins/wp-stateless-wpforms-addonProvides compatibility between the WPForms and the WP-Stateless plugins.
Is WP-Stateless – WPForms Addon Safe to Use in 2026?
Generally Safe
Score 92/100WP-Stateless – WPForms Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-stateless-wpforms-addon plugin v0.0.2 exhibits a concerning security posture due to a lack of proper authentication checks on all its AJAX handlers. While the static analysis reveals no dangerous functions, SQL injection vulnerabilities, or improper output escaping, the presence of four AJAX handlers without authentication checks represents a significant attack surface. This means that any user, regardless of their role or permissions, could potentially trigger these AJAX actions, leading to unintended consequences or further exploitation if the actions themselves have security flaws that are not immediately apparent from the provided metrics.
The plugin demonstrates good practices in other areas, such as 100% usage of prepared statements for SQL queries and proper output escaping, which are crucial for preventing common web vulnerabilities. The absence of any recorded vulnerabilities in its history is also a positive indicator. However, the critical weakness in its authentication mechanism for AJAX handlers cannot be overlooked. This oversight significantly increases the risk profile of the plugin, as it bypasses WordPress's built-in access control mechanisms.
In conclusion, while the plugin avoids several common pitfalls like raw SQL and unescaped output, the unprotected AJAX handlers are a major security concern that outweighs these strengths. The lack of taint analysis data is also a minor weakness, as it limits a deeper understanding of potential data manipulation risks. The overall security is compromised by the exposed AJAX functionality.
Key Concerns
- AJAX handlers without auth checks
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
WP-Stateless – WPForms Addon Security Vulnerabilities
WP-Stateless – WPForms Addon Code Analysis
SQL Query Safety
Output Escaping
WP-Stateless – WPForms Addon Attack Surface
AJAX Handlers 4
WordPress Hooks 13
Maintenance & Trust
WP-Stateless – WPForms Addon Maintenance & Trust
Maintenance Signals
Community Trust
WP-Stateless – WPForms Addon Alternatives
WP-Stateless – Gravity Forms Addon
wp-stateless-gravity-forms-addon
Provides compatibility between the Gravity Forms and the WP-Stateless plugins.
WP-Stateless – Elementor Website Builder Addon
wp-stateless-elementor-website-builder-addon
Provides compatibility between the Elementor Website Builder and the WP-Stateless plugins.
WP-Stateless – WooCommerce Addon
wp-stateless-woocommerce-addon
Provides compatibility between the WooCommerce and the WP-Stateless plugins.
WP-Stateless – LiteSpeed Cache Addon
wp-stateless-litespeed-cache-addon
Provides compatibility between the LiteSpeed Cache and the WP-Stateless plugins.
WP-Stateless – Divi Theme Addon
wp-stateless-divi-theme-addon
Provides compatibility between the Divi theme and the WP-Stateless plugin.
WP-Stateless – WPForms Addon Developer Profile
15 plugins · 5K total installs
How We Detect WP-Stateless – WPForms Addon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-stateless-wpforms-addon/dist/css/wpforms-stateless.css/wp-content/plugins/wp-stateless-wpforms-addon/dist/js/wpforms-stateless.js/wp-content/plugins/wp-stateless-wpforms-addon/dist/js/wpforms-stateless.jswp-stateless-wpforms-addon/dist/css/wpforms-stateless.css?ver=wp-stateless-wpforms-addon/dist/js/wpforms-stateless.js?ver=