Not secure
-
I would not recommend this form plugin, first off I have used it for more than 10 years, really like the way you can customize it and make it look like you want it with some markup and styles. However, the form displays a form ID in the markup, in addition to that it relies on wp-json to send form. In other words, very unsophisticated bot can trigger form submission with ease. Everything is exposed and insecure. Hashing a form ID would go a long way.
You must be logged in to reply to this review.