
Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Security & Risk Analysis
wordpress.org/plugins/zoho-formsTry Zoho Forms, the best WordPress contact form plugin! Create contact, payment & custom forms with a drag and drop builder. Get started for free!
Is Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Safe to Use in 2026?
Generally Safe
Score 98/100Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "zoho-forms" v4.0.4 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals no direct SQL injection vulnerabilities due to the use of prepared statements and a limited attack surface with no unprotected entry points identified. The absence of dangerous functions, file operations, and external HTTP requests is also commendable. However, the plugin's vulnerability history is a significant concern, with three previously disclosed medium-severity vulnerabilities, primarily related to Cross-Site Scripting (XSS). The fact that the last known vulnerability was very recent (September 30, 2024) and that there are currently no unpatched CVEs suggests that while vulnerabilities have been addressed, the plugin has a history of introducing such issues, requiring diligent patching.
While the current static analysis doesn't reveal active, exploitable vulnerabilities in this specific version, the pattern of past XSS vulnerabilities indicates a potential weakness in output escaping or input sanitization that could be re-introduced in future updates or might still be present in subtle ways not caught by the static analysis tools. The unescaped output rate of 25% (3 out of 12 outputs) is a point of concern, as even a single unescaped output can lead to XSS if user-supplied data is involved. The presence of the bundled TinyMCE library also warrants attention, as outdated versions of bundled libraries can introduce security risks. Despite a clean taint analysis in this version, the historical pattern and minor output escaping issues necessitate caution.
Key Concerns
- History of 3 medium severity CVEs
- 25% of outputs are not properly escaped
- Bundled library (TinyMCE) can pose risk
Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Zoho Forms <= 4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Zoho Forms <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Zoho Forms <= 3.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Release Timeline
Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Code Analysis
Bundled Libraries
Output Escaping
Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Maintenance & Trust
Maintenance Signals
Community Trust
Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Alternatives
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform
embed-form
Create and embed secure online forms in WordPress using Jotform’s drag-and-drop builder, with PCI and HIPAA compliance and full data-security support.
Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder
gutena-forms
WordPress form builder to create lightweight contact forms, survey forms, feedback forms, booking forms, etc., right inside the block editor.
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms
happyforms
Best WordPress contact form, newsletter form and payment form builder without the sucky stuff — lost emails, pesky spam, leaky privacy and outsourced …
فرم ساز فرم افزار
formafzar
ابزاری آسان برای ساخت فرمهای آنلاین قدرتمند بصورت حرفهای، به آسانی و کمتر از چند دقیقه فرم خودتون رو بسازید و به اشتراک بگذارید
Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More Developer Profile
6 plugins · 43K total installs
How We Detect Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zoho-forms/zohoforms-block.js/wp-content/plugins/zoho-forms/tinymce/zforms_editor_plugin.js/wp-content/plugins/zoho-forms/zohoforms-block.css/wp-content/plugins/zoho-forms/tinymce/zFormsIcon.png/wp-content/plugins/zoho-forms/tinymce/zforms_editor_plugin.jsHTML / DOM Fingerprints
zf-WpPopupContainerzf-WpMainWrapzf-WpFormPermaWrapzf-WpEmbeddedWrapzf-EmbedInnerzf-WpEmbeddedHeadzf-WpEmbeddedContainerembeddedPublicLink+1 moreid="zf_embedCatogory"id="zf_tiny_homeDiv"id="permaLinkDiv"id="permaContainer"id="permalink"zohoFormsBlockzforms_dailog.js[zohoForms src="[zohoForms src='<iframe height=<div id="zf_div_