
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Security & Risk Analysis
wordpress.org/plugins/wpzoom-formsDrag & drop contact form builder for WordPress. Create contact forms, custom forms, email forms with spam protection. Works with Elementor, shortcodes
Is WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Safe to Use in 2026?
Generally Safe
Score 100/100WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "wpzoom-forms" v1.3.7 presents a generally positive security posture based on the provided static analysis. A notable strength is the absence of known vulnerabilities (CVEs) and the presence of numerous capability checks and nonces, indicating an effort to secure its entry points. The plugin also demonstrates good practices in output escaping, with a high percentage of outputs being properly escaped.
However, there are a few areas of concern. The presence of a single SQL query without prepared statements is a potential risk, as it could be susceptible to SQL injection if the input is not rigorously sanitized. Furthermore, the taint analysis revealed one flow with an unsanitized path, which, while not classified as critical or high severity in this analysis, represents a potential avenue for unintended data manipulation or access if not properly handled downstream. The plugin's limited attack surface and lack of critical vulnerabilities in its history are encouraging signs.
Key Concerns
- Raw SQL query without prepared statement
- Flow with unsanitized path in taint analysis
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Security Vulnerabilities
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 47
Maintenance & Trust
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Alternatives
Weavely – Build Forms in Figma
weavely
Turn Figma designs into custom forms, effortlessly embed in WordPress. Elevate user experience with unique designs.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
Ninja Forms – The Contact Form Builder That Grows With You
ninja-forms
The 100% beginner friendly WordPress form builder. Drag & drop form fields to build beautiful, professional contact forms in minutes.
SureForms – Contact Form, Payment Form & Other Custom Form Builder
sureforms
The most beginner-friendly, AI Form Builder for WordPress to create contact forms, payment forms & other custom forms with advanced features, with …
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress Developer Profile
24 plugins · 337K total installs
How We Detect WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpzoom-forms/build/index.js/wp-content/plugins/wpzoom-forms/build/style-index.css/wp-content/plugins/wpzoom-forms/classes/notice-center/assets/notice-center.css/wp-content/plugins/wpzoom-forms/classes/notice-center/assets/notice-center.js/wp-content/plugins/wpzoom-forms/build/index.jswpzoom-forms/build/index.js?ver=wpzoom-forms/build/style-index.css?ver=HTML / DOM Fingerprints
wpzf-form-fieldwpzf-form-labelwpzf-form-inputwpzf-form-textareawpzf-form-selectwpzf-form-buttonWPZOOM Forms - Custom forms for WordPress, by WPZOOM.WPZOOM Notice Center (submodule at classes/notice-center).data-wpzf-form-iddata-wpzf-field-idWPZOOM_FORMS_VERSIONwpzoom_forms_ajax_object/wp-json/wpzoom-forms/v1/submit/wp-json/wpzoom-forms/v1/settings[wpzoom_forms id="[wpzoom_form id="