Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder
by 10Web · Forms
Also makes 7 other plugins · 223.9K+ installs across the portfolio →
Form Maker is a user-friendly contact form builder that allows to create forms for any purpose, from a simple contact form to multi page survey forms
88 health vs 63 average across 1,679 Forms plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
27.2K
now · peak 75.0K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
10
releases in the last 12 months
3mo ago
latest release · v1.15.44
347
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin · 79% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “30K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2015-06-01 · 1,500 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.
Details
Recent reviews
All reviews on wp.org ↗- ★★★★★ Havyarimana Fabien2mo ago
It works well both on mobile and desktop devices and compatible with WordPress plugins and themes.
Read on wp.org ↗ - ★★★★★ wireB7mo ago
Is there a PDF form filler?
Read on wp.org ↗ - ★★★★★ robert4331.9y ago
My partner complained about the huge spam emails received from the contact page. I initially thought of hiring a freelancer to add some kind of human validation for the Contact 7 form. Then I searched the website and found this plugin WP Image CAPTCHA. After I installed and activated it, add those two words per the instruction, and then I got the working contact 7 form with WP Image CAPTCHA. Very easy to add. Thanks a lot!
Read on wp.org ↗ - ★★★★★ donademadona2.4y ago
Good plugin
Read on wp.org ↗ - ★★★★★ dvelkov2.5y ago
On their page you will find a option to “Buy Now”, but it does not clearly states that you are SUBSCRIBING for a 6 month billing period. When you ask for a refund: “No refund is provided. There is a 7 day free trial.”. You can be sure that nowhere on the page you can “Free trial” button or option. So I paid for the full function, saw it does not work for me as the added functionality is very small. So now I am stuck with a useless PREMIUN version! |ZERO STARS!!!
Read on wp.org ↗ - ★★★★★ shakedown19792.6y ago
Very simple, yet effective. The customization if fails easy too.
Read on wp.org ↗ - ★★★★★ s4mr4t3.0y ago
good
Read on wp.org ↗ - ★★★★★ Marisa Salinas3.1y ago
Lots of options and very customizable.
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
Known vulnerabilities
via Wordfence Intelligence42 disclosed vulnerabilities on record for this plugin, 1 still affects the current version.
- 2026-08-19 CVE-2026-66616 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.46 No patch available
- 2026-08-14 CVE-2026-15993 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.15.44 Patched in 1.15.45
- 2026-08-10 CVE-2026-16977 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.15.44 Patched in 1.15.45
- Medium · 4.9 Form Maker by 10Web <= 1.15.43 - Authenticated (Adminsitrator+) SQL Injection via 'groupids' Parameter ↗2026-06-17 CVE-2026-11776 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.15.43 Patched in 1.15.44
- Medium · 4.9 Form Maker by 10Web <= 1.15.43 - Authenticated (Administrator+) SQL Injection via 'name' Parameter ↗2026-06-17 CVE-2026-11777 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.15.43 Patched in 1.15.44
- 2026-05-04 CVE-2026-3359 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.15.42 Patched in 1.15.43
- Medium · 4.9 Form Maker by 10Web <= 1.15.40 - Authenticated (Administrator+) SQL Injection via 'ip_search' Parameter ↗2026-04-16 CVE-2026-3330 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.15.40 Patched in 1.15.41
- 2026-04-13 CVE-2026-4388 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.40 Patched in 1.15.41
- 2026-04-08 CVE-2026-39502 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.15.38 Patched in 1.15.39
- 2026-03-23 CVE-2025-15441 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.15.38 Patched in 1.15.38
- High · 7.1 Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via Hidden Field ↗2026-02-02 CVE-2026-1058 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.35 Patched in 1.15.36
- High · 7.2 Form Maker by 10Web <= 1.15.35 - Unauthenticated Stored Cross-Site Scripting via SVG file ↗2026-02-02 CVE-2026-1065 Unrestricted Upload of File with Dangerous Type Affects <= 1.15.35 Patched in 1.15.36
- Medium · 4.4 Form Maker by 10Web <= 1.15.33 - Authenticated (Administrator+) Stored Cross-Site Scripting ↗2025-05-19 CVE-2025-48341 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.33 Patched in 1.15.34
- Medium · 5.5 Form Maker by 10Web <= 1.15.31 - Authenticated (Administrator+) Stored Cross-Site Scripting ↗2025-03-26 CVE-2024-10680 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.31 Patched in 1.15.32
- 2025-03-03 CVE-2024-10560 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.29 Patched in 1.15.30
- 2025-03-02 CVE-2024-10558 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.29 Patched in 1.15.30
- 2025-02-07 CVE-2024-13053 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.32 Patched in 1.15.33
- 2025-02-03 CVE-2024-13605 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.32 Patched in 1.15.33
- 2024-12-17 CVE-2024-10562 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.30 Patched in 1.15.31
- 2024-12-03 CVE-2024-5020 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.27 Patched in 1.15.28
- 2024-11-10 CVE-2024-10265 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.30 Patched in 1.15.31
- 2024-09-25 CVE-2024-8633 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.27 Patched in 1.15.28
- 2024-08-09 CVE-2024-43220 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.26 Patched in 1.15.27
- 2024-06-10 CVE-2024-6130 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.25 Patched in 1.15.26
- Medium · 4.4 Form Maker by 10Web <= 1.15.24 - Authenticated (Administrator+) Stored Cross-Site Scripting ↗2024-05-07 CVE-2024-34437 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.24 Patched in 1.15.25
- Medium · 4.4 Form Maker by 10Web <= 1.15.24 - Authenticated (Subscriber+) Stored Self-Based Cross-Site Scripting ↗2024-04-26 CVE-2024-2258 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.24 Patched in 1.15.25
- 2024-04-15 CVE-2024-32534 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.23 Patched in 1.15.24
- Medium · 5.4 Form-Maker (twb_form-maker) <= 1.15.21 - Cross-Site Request Forgery to Limited Code Execution via Execute ↗2024-01-26 CVE-2024-0667 Inappropriate Source Code Style or Formatting Affects <= 1.15.21 Patched in 1.15.22
- Medium · 5.3 Form Maker <= 1.15.20 - Captcha Bypass ↗
- 2023-10-03 CVE-2023-45071 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.18 Patched in 1.15.19
- 2023-10-03 CVE-2023-45070 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.18 Patched in 1.15.19
- 2023-09-07 CVE-2023-4666 Unrestricted Upload of File with Dangerous Type Affects < 1.15.20 Patched in 1.15.20
- 2023-06-14 Missing Authorization Affects <= 1.15.16 Patched in 1.15.17
- 2022-09-29 CVE-2022-3300 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.15.5 Patched in 1.15.6
- 2022-05-09 CVE-2022-1564 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.14.11 Patched in 1.14.12
- 2021-07-15 CVE-2021-24526 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.13.59 Patched in 1.13.60
- 2020-07-12 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.13.40 Patched in 1.13.40
- 2020-05-26 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.13.35 Patched in 1.13.36
- 2019-05-10 CVE-2019-10866 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.13.3 Patched in 1.13.3
- 2018-04-27 CVE-2018-10504 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects < 1.12.22 Patched in 1.12.22
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 59 languages, 1 at 90% or more
Plus 35 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2026-04-04 40K+ → 30K+ down after 355 days in tier
- 2025-04-14 50K+ → 40K+ down after 356 days in tier
- 2024-04-23 60K+ → 50K+ down after 284 days in tier
- 2023-07-14 70K+ → 60K+ down after 262 days in tier
- 2022-10-25 80K+ → 70K+ down
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder with AI 90K+ installs · 4.8★ · 3 shared tags A
-
Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder 10K+ installs · 4.9★ · 3 shared tags A -
Gutenverse Form – Contact Form Builder, Block Form & Booking Form 10K+ installs · 4.0★ · 3 shared tags B -
Survey Maker by AYS 5K+ installs · 4.7★ · 3 shared tags A -
Smart Forms – when you need more than just a contact form 5K+ installs · 4.5★ · 3 shared tags A -
Hash Form – Drag & Drop Form Builder 3K+ installs · 4.1★ · 3 shared tags B
Embed this report card
Drop a live Pulse card for Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/form-maker" width="480" height="300" style="border:0" loading="lazy" title="Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder — Plugin Pulse"></iframe> Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder: 30K+ active installs, 4.5★ (777 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/form-maker