| #51 | Block IPs for Gravity Forms | 50 | 8 | 36 | 1k+ | | | Request data is not unslashed |
| #52 | Formstack Online Forms | 52 | 39 | 20 | 1k+ | | | Output is not escaped |
| #53 | File Upload For WPForms – Filenzo | 59 | 8 | 16 | 1k+ | | | Output is not escaped |
| #54 | Wrap form fields in Gravity Forms | 84 | 22 | 3 | 1k+ | | | Text Domain Mismatch |
| #55 | Universal Honey Pot | 40 | 23 | 94 | 1k+ | | | Missing nonce verification |
| #56 | Woorise – Landing Pages, Forms & Surveys | 71 | 8 | 14 | 1k+ | | | Input is not sanitized |
| #57 | Retainful – WooCommerce Abandoned Cart, Newsletters, Email Marketing, Signup Forms and Automation | 79 | 15 | 26 | 1k+ | | | Non-prefixed hook name |
| #58 | GravityWP – Count | 98 | 2 | 3 | 2k+ | | | trademarked term |
| #59 | Subscribe Forms – Beautiful Email Forms, Embedded Newsletter Forms & MailChimp Form | 23 | 419 | 542 | 2k+ | | | Non-prefixed global variable |
| #60 | Edit Entries for Gravity Forms | 91 | 5 | 3 | 2k+ | | | Nonce verification recommended |
| #61 | Account Engagement | 32 | 115 | 74 | 2k+ | | | Output is not escaped |
| #62 | WP-FormAssembly | 77 | 4 | 15 | 2k+ | | | Nonce verification recommended |
| #63 | Cognito Forms | 75 | 13 | 4 | 2k+ | | | wp function not compatible with requires wp |
| #64 | Gravity Forms – Placeholders add-on | 90 | 5 | 5 | 2k+ | | | trademarked term |
| #65 | Fluent Forms Block | 92 | 4 | 18 | 2k+ | | | Non-prefixed global variable |
| #66 | Gravity Slider Fields | 39 | 56 | 36 | 2k+ | | | Text Domain Mismatch |
| #67 | G-Forms hCaptcha | 88 | 7 | 5 | 3k+ | | | Missing direct file access protection |
| #68 | Payment Forms for Paystack | 90 | 494 | 23 | 3k+ | | | Text Domain Mismatch |
| #69 | Gravity Forms Constant Contact | 46 | 36 | 27 | 3k+ | | | Non-prefixed class |
| #70 | Mollie Forms | 41 | 14 | 565 | 3k+ | | | Request data is not unslashed |
| #71 | Quill Forms | Conversational Multi Step Forms, Surveys & quizzes | 20 | 401 | 368 | 3k+ | | | Text Domain Mismatch |
| #72 | Add-on Contact Form 7 – MailPoet 3 | 41 | 88 | 12 | 3k+ | | | Output is not escaped |
| #73 | GravityWP – CSS Selector | 98 | 2 | 4 | 4k+ | | | trademarked term |
| #74 | Gravity Forms CSS Ready Class Selector | 72 | 18 | 4 | 4k+ | | | Non Singular String Literal Domain |
| #75 | Country State City Dropdown CF7 | 40 | 35 | 54 | 5k+ | | | Direct Query |
| #76 | Smart Forms – when you need more than just a contact form | 21 | 776 | 574 | 5k+ | | | Output is not escaped |
| #77 | Contact Form 7 Signature Addon | 45 | 147 | 44 | 6k+ | | | Text Domain Mismatch |
| #78 | Integration for Elementor forms – Sendinblue | 65 | 94 | 56 | 7k+ | | | Text Domain Mismatch |
| #79 | Lead Form Builder & Contact Form | 35 | 400 | 345 | 9k+ | | | Output is not escaped |
| #80 | Multi Step Form | 34 | 277 | 136 | 9k+ | | | Output is not escaped |
| #81 | WS Form LITE – Drag & Drop Contact Form Builder | 100 | | 0 | 10k+ | | | No open findings |
| #82 | Zoho Forms – Drag & Drop Form Builder for Websites – Contact Forms, Payment Forms, Order Forms & More | 85 | 16 | 2 | 10k+ | | | Non Enqueued Script |
| #83 | SendWP | 37 | 47 | 42 | 10k+ | | | Output is not escaped |
| #84 | Multi Step for Contact Form 7 | 36 | 61 | 106 | 10k+ | | | Missing nonce verification |
| #85 | weForms – Easy Drag & Drop Contact Form Builder For WordPress | 25 | 916 | 450 | 10k+ | | | Output is not escaped |
| #86 | WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress | 35 | 74 | 109 | 10k+ | | | Nonce verification recommended |
| #87 | Visual Form Builder | 34 | 82 | 329 | 20k+ | | | Direct Query |
| #88 | Online Forms — Customizable Payment, Contact, Quiz, Survey Form Builder – Jotform | 99 | 1 | 0 | 20k+ | | | outdated tested upto header |
| #89 | RD Station | 74 | 2 | 67 | 20k+ | | | Non-prefixed global variable |
| #90 | Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms | 22 | 1,037 | 722 | 20k+ | | | Unsafe printing function |
| #91 | Database Addon For WPForms ( wpforms entries ) – WPFormsDB | 43 | 17 | 53 | 20k+ | | | Nonce verification recommended |
| #92 | Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder | 37 | 83 | 113 | 20k+ | | | SQL query is not prepared |
| #93 | Contact Form & SMTP Plugin for WordPress by PirateForms | 93 | 14 | 102 | 30k+ | | | Non-prefixed hook name |
| #94 | Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI | 23 | 395 | 1,342 | 90k+ | | | Non-prefixed global variable |
| #95 | Conditional Fields for Contact Form 7 | 41 | 113 | 52 | 100k+ | | | Output is not escaped |
| #96 | Crowdsignal Forms | 100 | | 0 | 200k+ | | | No open findings |
| #97 | CMB2 | 36 | 148 | 19 | 300k+ | | | Output is not escaped |
| #98 | Forminator Forms – Contact Form, Payment Form & Custom Form Builder | 24 | 826 | 1,314 | 600k+ | | | Non-prefixed global variable |
| #99 | Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder | 22 | 409 | 236 | 700k+ | | | Text Domain Mismatch |