WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Security & Risk Analysis

wordpress.org/plugins/wpzoom-forms

Drag & drop contact form builder for WordPress. Create contact forms, custom forms, email forms with spam protection. Works with Elementor, shortcodes

10K active installs v1.3.7 PHP 7.4+ WP 6.5+ Updated Mar 15, 2026
contactcontact-formemail-formform-builderforms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 19d ago
Risk Assessment

The plugin "wpzoom-forms" v1.3.7 presents a generally positive security posture based on the provided static analysis. A notable strength is the absence of known vulnerabilities (CVEs) and the presence of numerous capability checks and nonces, indicating an effort to secure its entry points. The plugin also demonstrates good practices in output escaping, with a high percentage of outputs being properly escaped.

However, there are a few areas of concern. The presence of a single SQL query without prepared statements is a potential risk, as it could be susceptible to SQL injection if the input is not rigorously sanitized. Furthermore, the taint analysis revealed one flow with an unsanitized path, which, while not classified as critical or high severity in this analysis, represents a potential avenue for unintended data manipulation or access if not properly handled downstream. The plugin's limited attack surface and lack of critical vulnerabilities in its history are encouraging signs.

Key Concerns

  • Raw SQL query without prepared statement
  • Flow with unsanitized path in taint analysis
Vulnerabilities
None known

WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
28
205 escaped
Nonce Checks
2
Capability Checks
10
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

88% escaped233 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
custom_filter_by_form (wpzoom-forms.php:1265)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_wpzoom_reset_settingsclasses\class-wpzoom-forms-settings-page.php:81

Shortcodes 1

[wpzf_form] wpzoom-forms.php:376
WordPress Hooks 47
actionadmin_initclasses\class-wpzoom-forms-settings-page.php:74
actionadmin_initclasses\class-wpzoom-forms-settings-page.php:75
actionadmin_enqueue_scriptsclasses\class-wpzoom-forms-settings-page.php:78
actionwpzoom_forms_admin_pageclasses\class-wpzoom-forms-settings-page.php:85
actionwpzoom_forms_admin_page_upsellclasses\class-wpzoom-forms-settings-upsell.php:7
actionadmin_enqueue_scriptsclasses\class-wpzoom-forms-template-manager.php:48
actionadmin_footerclasses\class-wpzoom-forms-template-manager.php:49
filterdefault_contentclasses\class-wpzoom-forms-template-manager.php:50
actionelementor/initelementor\wpzoom-forms-elementor.php:49
actionelementor/elements/categories_registeredelementor\wpzoom-forms-elementor.php:66
actionelementor/widgets/registerelementor\wpzoom-forms-elementor.php:67
actionelementor/editor/before_enqueue_scriptselementor\wpzoom-forms-elementor.php:69
actioninitwpzoom-forms.php:57
filterallowed_block_types_allwpzoom-forms.php:161
filterblock_categories_allwpzoom-forms.php:162
filterpost_row_actionswpzoom-forms.php:163
filterbulk_actions-edit-wpzf-formwpzoom-forms.php:164
filterbulk_actions-edit-wpzf-submissionwpzoom-forms.php:165
filtermanage_edit-wpzf-form_columnswpzoom-forms.php:166
filtermanage_edit-wpzf-submission_columnswpzoom-forms.php:167
filtermanage_edit-wpzf-submission_sortable_columnswpzoom-forms.php:168
filterscreen_options_show_screenwpzoom-forms.php:169
filterviews_edit-wpzf-formwpzoom-forms.php:170
filterlist_table_primary_columnwpzoom-forms.php:171
actionadmin_menuwpzoom-forms.php:172
actionadmin_enqueue_scriptswpzoom-forms.php:173
actionenqueue_block_editor_assetswpzoom-forms.php:174
actionenqueue_block_assetswpzoom-forms.php:175
actionenqueue_block_assetswpzoom-forms.php:176
actionwp_enqueue_scriptswpzoom-forms.php:177
actionall_admin_noticeswpzoom-forms.php:178
actionin_admin_footerwpzoom-forms.php:179
filteradmin_body_classwpzoom-forms.php:180
actionmanage_wpzf-form_posts_custom_columnwpzoom-forms.php:181
actionmanage_wpzf-submission_posts_custom_columnwpzoom-forms.php:182
actionpre_get_postswpzoom-forms.php:183
actionin_admin_headerwpzoom-forms.php:184
actionadd_meta_boxes_wpzf-submissionwpzoom-forms.php:185
actionadmin_post_wpzf_submitwpzoom-forms.php:186
actionadmin_post_nopriv_wpzf_submitwpzoom-forms.php:187
actionrestrict_manage_postswpzoom-forms.php:189
actionparse_querywpzoom-forms.php:190
filterwpzoom_notice_center_noticeswpzoom-forms.php:193
filterpost_date_column_statuswpzoom-forms.php:492
filterpost_date_column_timewpzoom-forms.php:493
filterpost_date_column_statuswpzoom-forms.php:525
actionplugin_loadedwpzoom-forms.php:3275
Maintenance & Trust

WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedMar 15, 2026
PHP min version7.4
Downloads218K

Community Trust

Rating100/100
Number of ratings2
Active installs10K
Developer Profile

WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Developer Profile

WPZOOM

24 plugins · 337K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
102 days
View full developer profile
Detection Fingerprints

How We Detect WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpzoom-forms/build/index.js/wp-content/plugins/wpzoom-forms/build/style-index.css/wp-content/plugins/wpzoom-forms/classes/notice-center/assets/notice-center.css/wp-content/plugins/wpzoom-forms/classes/notice-center/assets/notice-center.js
Script Paths
/wp-content/plugins/wpzoom-forms/build/index.js
Version Parameters
wpzoom-forms/build/index.js?ver=wpzoom-forms/build/style-index.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpzf-form-fieldwpzf-form-labelwpzf-form-inputwpzf-form-textareawpzf-form-selectwpzf-form-button
HTML Comments
WPZOOM Forms - Custom forms for WordPress, by WPZOOM.WPZOOM Notice Center (submodule at classes/notice-center).
Data Attributes
data-wpzf-form-iddata-wpzf-field-id
JS Globals
WPZOOM_FORMS_VERSIONwpzoom_forms_ajax_object
REST Endpoints
/wp-json/wpzoom-forms/v1/submit/wp-json/wpzoom-forms/v1/settings
Shortcode Output
[wpzoom_forms id="[wpzoom_form id="
FAQ

Frequently Asked Questions about WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress