
WPCasa Ninja Forms Security & Risk Analysis
wordpress.org/plugins/wpcasa-ninja-formsAdds support for Ninja Forms 3.0 an above to attach property details to the contact email sent from WPCasa listing pages. Support for Ninja Forms belo …
Is WPCasa Ninja Forms Safe to Use in 2026?
Generally Safe
Score 100/100WPCasa Ninja Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'wpcasa-ninja-forms' v2.0.1 exhibits a strong security posture based on the static analysis and vulnerability history. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code analysis shows a healthy approach to security with a notable lack of dangerous functions, 100% of SQL queries utilizing prepared statements, and a high percentage of output properly escaped. The plugin also demonstrates good practices by not making external HTTP requests and avoiding bundled libraries.
However, there are some areas that warrant attention. The complete lack of nonce checks and capability checks across all identified entry points is a significant concern. While the static analysis found no AJAX handlers or REST API routes without authentication, the absence of these checks suggests that if any such entry points were to be introduced in future updates, they might be vulnerable by default. The single file operation could also pose a risk if not handled with extreme care regarding user-supplied input. The zero vulnerability history is a positive sign, indicating a well-maintained plugin, but it does not negate the importance of implementing robust security mechanisms like nonce and capability checks to guard against potential future vulnerabilities.
In conclusion, the plugin is strong in its current implementation, with excellent data sanitization and secure database interactions. The primary weakness lies in the absence of authorization checks, which is a fundamental security practice for WordPress plugins. Addressing this would elevate the plugin's security to an even higher standard.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
- Unescaped Output (minor)
- File Operation without detailed analysis
WPCasa Ninja Forms Security Vulnerabilities
WPCasa Ninja Forms Code Analysis
Output Escaping
WPCasa Ninja Forms Attack Surface
WordPress Hooks 11
Maintenance & Trust
WPCasa Ninja Forms Maintenance & Trust
Maintenance Signals
Community Trust
WPCasa Ninja Forms Alternatives
Advanced Custom Fields: Ninjaforms Add-on
acf-ninjaforms-add-on
Advanced Custom Field with which we can select Ninjaforms.
Ninja Forms Merge Tag Addon
nf-merge-tag-addon
Add new merge tags for WordPress Ninja Forms. More Tags are coming soon!
API for Ninja Forms
api-for-ninja-forms
A REST API for Ninja Forms that supports JSON and PDF output.
WP Contact Slider – Contact Form Slider Widget
wp-contact-slider
Helps you to show slide out contact form to display CF7, Gravity forms, Ninja Forms, WP Forms, display random text/HTML and support some other forms.
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-mailchimp
Send Contact Form 7, WPforms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to Mailchimp.
WPCasa Ninja Forms Developer Profile
10 plugins · 3K total installs
How We Detect WPCasa Ninja Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpcasa-ninja-forms/assets/css/wpsight-ninja-forms.csswpsight-ninja-forms.css?ver=wpcasa-ninja-forms/assets/css/wpsight-ninja-forms.css?ver=HTML / DOM Fingerprints
[ninja_form id=