Form WordPress Plugins That Need Review
58 indexed plugins
Plugins
58
Active Installs
2m+
Average Score
51
Audited
58
Needs Review
| Rank | Plugin | Score | Errors | Warnings | Installs | Added | Updated | Top Issue |
|---|---|---|---|---|---|---|---|---|
| #1 | Smart Forms – when you need more than just a contact form | 21 | 776 | 574 | 5k+ | Output is not escaped | ||
| #2 | E2Pdf – Export Pdf Tool for WordPress | 22 | 1,075 | 836 | 10k+ | Unsafe printing function | ||
| #3 | Quick Contact Form | 22 | 260 | 623 | 1k+ | Non-prefixed function | ||
| #4 | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | 23 | 4,746 | 1,279 | 30k+ | Non Singular String Literal Domain | ||
| #5 | Subscribe Forms – Beautiful Email Forms, Embedded Newsletter Forms & MailChimp Form | 23 | 419 | 542 | 2k+ | Non-prefixed global variable | ||
| #6 | Calculated Fields Form | 24 | 282 | 599 | 40k+ | Non-prefixed global variable | ||
| #7 | Iptanus File Upload | 24 | 509 | 1,325 | 10k+ | Non-prefixed function | ||
| #8 | Contact Form Email | 25 | 409 | 898 | 9k+ | Non-prefixed global variable | ||
| #9 | Survey Maker by AYS | 25 | 566 | 2,397 | 6k+ | Non-prefixed global variable | ||
| #10 | User Avatar | 26 | 104 | 173 | 4k+ | Non-prefixed constant | ||
| #11 | MW WP Form | 27 | 334 | 219 | 200k+ | Output is not escaped | ||
| #12 | Laposta Signup Basic | 28 | 275 | 66 | 2k+ | Output is not escaped | ||
| #13 | Formzu WP | 30 | 167 | 163 | 3k+ | Text Domain Mismatch | ||
| #14 | cformsII | 31 | 777 | 536 | 4k+ | Unsafe printing function | ||
| #15 | Advanced Forms for ACF | 33 | 169 | 278 | 3k+ | Non-prefixed hook name | ||
| #16 | Contact Form Plugin | 33 | 47 | 220 | 2k+ | Non-prefixed function | ||
| #17 | Forms: 3rd-Party Integration | 34 | 234 | 112 | 5k+ | Output is not escaped | ||
| #18 | RTMForm Builder | 34 | 188 | 209 | 30k+ | Text Domain Mismatch | ||
| #19 | Visual Form Builder | 34 | 82 | 329 | 20k+ | Direct Query | ||
| #20 | Newsletters, Email Marketing, SMS and Popups by Omnisend | 35 | 5 | 2 | 100k+ | Hidden files included | ||
| #21 | Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder | 36 | 3 | 321 | 10k+ | Nonce verification recommended | ||
| #22 | HTML Forms – Simple WordPress Forms Plugin | 36 | 231 | 166 | 10k+ | Output is not escaped | ||
| #23 | MailerLite – Signup forms (official) | 36 | 430 | 158 | 100k+ | Output is not escaped | ||
| #24 | PDF Forms Filler for CF7 | 36 | 185 | 79 | 3k+ | Text Domain Mismatch | ||
| #25 | Send PDF for Contact Form 7 | 37 | 22 | 308 | 9k+ | Non-prefixed global variable | ||
| #26 | Contact Form 7 – Post Fields | 38 | 167 | 25 | 3k+ | Text Domain Mismatch | ||
| #27 | Add-on Contact Form 7 – MailPoet 3 | 41 | 88 | 12 | 3k+ | Output is not escaped | ||
| #28 | Conditional Fields for Contact Form 7 | 41 | 113 | 52 | 100k+ | Output is not escaped | ||
| #29 | Confetti | 42 | 136 | 17 | 3k+ | Unsafe printing function | ||
| #30 | Contact Form 7 add confirm | 42 | 31 | 51 | 50k+ | Text Domain Mismatch | ||
| #31 | Hash Form – Drag & Drop Form Builder | 43 | 9 | 273 | 4k+ | Non-prefixed global variable | ||
| #32 | reCAPTCHA for MW WP Form | 43 | 37 | 14 | 30k+ | Non Singular String Literal Domain | ||
| #33 | Contact Form 7 Signature Addon | 45 | 147 | 44 | 6k+ | Text Domain Mismatch | ||
| #34 | wpDataTables integration for Forminator Forms | 45 | 62 | 38 | 1k+ | Text Domain Mismatch | ||
| #35 | WP Login Form | 48 | 14 | 20 | 7k+ | Request data is not unslashed | ||
| #36 | Confirm Plus Contact Form 7 | 49 | 19 | 36 | 7k+ | Non Singular String Literal Domain | ||
| #37 | VS Contact Form | 55 | 3 | 318 | 7k+ | Non-prefixed global variable | ||
| #38 | Gravity PDF | 57 | 116 | 152 | 20k+ | Non-prefixed global variable | ||
| #39 | MC4WP: Mailchimp for WordPress | 57 | 238 | 1m+ | Non-prefixed global variable | |||
| #40 | Gutenverse Form – Contact Form Builder, Block Form & Booking Form | 58 | 17 | 48 | 10k+ | Nonce verification recommended | ||
| #41 | GravityWP – Merge Tags | 59 | 16 | 172 | 2k+ | Non-prefixed global variable | ||
| #42 | Advanced Comment Form | 64 | 68 | 6 | 4k+ | Output is not escaped | ||
| #43 | Contact Form 7 Confirm Email Field | 71 | 35 | 11 | 2k+ | Text Domain Mismatch | ||
| #44 | Gravity Forms CSS Ready Class Selector | 72 | 18 | 4 | 4k+ | Non Singular String Literal Domain | ||
| #45 | Multifile Upload Field for Contact Form 7 | 73 | 41 | 7 | 5k+ | Text Domain Mismatch | ||
| #46 | Cognito Forms | 75 | 13 | 4 | 2k+ | wp function not compatible with requires wp | ||
| #47 | Advanced Custom Fields: Gravity Forms Add-on | 78 | 33 | 13 | 30k+ | Text Domain Mismatch | ||
| #48 | SurveyX Builder – Easy Feedback, Poll, Quiz & Survey | 81 | 22 | 2k+ | Interpolated SQL is not prepared | |||
| #49 | SearchWP Modal Search Form | 91 | 9 | 9 | 5k+ | trademarked term | ||
| #50 | Kit (formerly ConvertKit) for WPForms | 96 | 11 | 16 | 1k+ | Non-prefixed global variable |