Plugin Pulse
← Pulse

Forminator Forms – Contact Form, Payment Form & Custom Form Builder

by WPMU DEV - Your All-in-One WordPress Platform · Forms

Also makes 8 other plugins · 2.4M+ installs across the portfolio →

Best WordPress form builder plugin. Create contact forms, payment forms & order forms with 1000+ integrations.

How scoring works →
95 Health · A
Maintenance 100/100
Rating quality 97/100
Support 83/100

95 health vs 63 average across 1,678 Forms plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

96 / 100

Excellent listing optimization

Well tuned across the board

Update recency 100/100
WP compatibility 100/100
Rating quality 96/100
Listing tuning 100/100
Support resolution 77/100

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

+164% vs prior 30d
4.6KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

957.9K

now · peak 982.0K

962.7K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Forminator Forms · #102 you Formidable Forms · #174 Gutena Forms · #1180 Happyforms · #1281

Rating trend

Star average over time · dips mark rough releases

4.8Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

1.6Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

23

releases in the last 12 months

2mo ago

latest release · v1.55.1

129

tagged releases on record

Recent releases

1.55.1 · 2mo ago1.55.0.2 · 2mo ago1.55.0.1 · 2mo ago1.55.0 · 2mo ago1.54.0 · 3mo ago1.54 · 3mo ago1.53.2 · 3mo ago1.53.1 · 4mo ago1.53.0.1 · 4mo ago1.53.0 · 4mo ago1.52.2 · 5mo ago1.52.1 · 5mo ago1.52 · 5mo ago1.51.1 · 6mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v1.55 50%
v1.53 6.4%
Older / other versions 44%

Estimated active installs

The public count shows “600K+”. Our estimate pins where the real number sits.

tracked estimate
600K–700K ≈690K

Refined from the date this plugin crossed into its current band.

Install history · since 2018-09-16 · 1,465 observations

600KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.

Details

Version
1.57.1
Last updated
yesterday
Added
2018-09-04 · 7 yrs old
Requires WP
6.4
Tested up to
7.1
Requires PHP
7.4

Recent review vibe

read from the latest 12 reviews to 2026-07-20
Positive PraiseFeature requests

Reviewers are consistently happy with Forminator's free feature set, ease of use and support, with only a passing request for submission-limit controls.

Recent reviews

All reviews on wp.org ↗
  1. techmesa
    1mo ago

    This plug in works great and and even lets you embed stripe payments on your forms – for free. Supports test and paid modes – PLUS conditions for when any part of the form is shown. You can even add different products and different pricces and show them based on conditions. Far better than I expected and you cant find these features in a free plug in anywhere.

    Read on wp.org ↗
  2. didier59450
    1mo ago

    Very good support, even when it’s complicated!

    Read on wp.org ↗
  3. Pamelita
    1mo ago

    Don´t you just love it when an plugin actually does what it says? And stays solid, up-to-date while easy to use. Excellent plugin.

    Read on wp.org ↗
  4. chief501
    2mo ago

    Great product! Fantastic free tool to manage forms and payments for my non-profit.

    Read on wp.org ↗
  5. 2ndchanceapartments
    2mo ago

    I am using for own my [redacted] website. This topic was modified 1 week, 3 days ago by Steven Stern (sterndata). Reason: removed link to site

    Read on wp.org ↗
  6. stincpao
    2mo ago

    I’ve used it for an online test with custom calculations for the result and custom results pages.

    Read on wp.org ↗
  7. jariapesland
    2mo ago

    I’ve used Forminator on multiple clients websites. I’ve never had an issue with it. I’ve also used it for fun quizzes on clients websites and everything works great.

    Read on wp.org ↗
  8. sicman
    2mo ago

    Vraiment top !

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. 2026-08-18 Version 1.57.1 Fix: Security issue affecting Multisite site registration (props: Jakub Herman) 1.57.1
  2. 2026-08-18 Version 1.57.0.8 Fix: Security issue affecting payment processing (props: Jakub Herman) 1.57.0.8
  3. 2026-08-18 Version 1.57.0.7 Fix: Privilege escalation vulnerability 1.57.0.7
  4. 2026-08-18 Version 1.57.0.6 Fix: Vulnerability – PHP Object Injection 1.57.0.6
  5. 2026-08-18 Version 1.57.0.5 Fix: Security improvements on Hub-Connector (props: Jakub Herman) 1.57.0.5
  6. 2026-08-18 Version 1.57.0.4 Fix: Cross-Site Scripting (XSS) vulnerability 1.57.0.4

Known vulnerabilities

via Wordfence Intelligence

52 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-08-24 CVE-2026-18328 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.57.0 Patched in 1.57.0.1
  2. 2026-08-24 CVE-2026-18323 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.57.0.2 Patched in 1.57.0.3
  3. 2026-08-19 CVE-2026-66583 Deserialization of Untrusted Data Affects <= 1.57.0 Patched in 1.57.1
  4. 2026-08-17 CVE-2026-15748 Unrestricted Upload of File with Dangerous Type Affects <= 1.56.1 Patched in 1.56.2
  5. 2026-08-15 CVE-2026-12998 Authorization Bypass Through User-Controlled Key Affects <= 1.55.0.2 Patched in 1.55.1
  6. 2026-08-05 CVE-2026-18325 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.56.1 Patched in 1.56.2
  7. 2026-08-03 CVE-2026-28143 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.56.0 Patched in 1.56.1
  8. 2026-08-03 CVE-2026-28111 Incorrect Privilege Assignment Affects <= 1.56.0 Patched in 1.56.0.1
  9. 2026-07-08 CVE-2026-57815 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 1.55.0.2 Patched in 1.55.1
  10. 2026-07-08 CVE-2026-57814 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.55.0.1 Patched in 1.55.0.2
  11. 2026-06-24 CVE-2026-56071 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.53.1 Patched in 1.53.2
  12. 2026-05-06 CVE-2026-6214 Missing Authorization Affects <= 1.53.0 Patched in 1.53.0.1
  13. 2026-05-06 CVE-2026-6222 Missing Authorization Affects <= 1.51.1 Patched in 1.52
  14. 2026-05-04 CVE-2026-5192 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 1.52.1 Patched in 1.52.2
  15. 2026-05-04 CVE-2026-2729 Authorization Bypass Through User-Controlled Key Affects <= 1.52.0 Patched in 1.52.1
  16. 2026-02-22 CVE-2026-32409 Missing Authorization Affects <= 1.50.2 Patched in 1.50.3
  17. 2026-02-16 CVE-2026-2002 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.50.2 Patched in 1.50.3
  18. 2026-01-08 CVE-2025-14782 Missing Authorization Affects <= 1.49.1 Patched in 1.49.2
  19. 2025-07-17 CVE-2025-7638 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.45.0 Patched in 1.45.1
  20. 2025-07-01 CVE-2025-6464 Deserialization of Untrusted Data Affects <= 1.44.2 Patched in 1.44.3
  21. 2025-07-01 CVE-2025-6463 External Control of File Name or Path Affects <= 1.44.2 Patched in 1.44.3
  22. 2025-06-04 CVE-2025-5341 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.44.1 Patched in 1.44.2
  23. 2025-04-16 CVE-2025-3487 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.42.0 Patched in 1.42.1
  24. 2025-04-16 CVE-2025-3479 Improper Validation of Integrity Check Value Affects <= 1.42.0 Patched in 1.42.1
  25. 2025-02-26 CVE-2025-0469 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 1.39.2 Patched in 1.39.3
  26. 2025-01-30 CVE-2025-0470 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.38.2 Patched in 1.38.3
  27. 2025-01-24 CVE-2024-7052 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.38.2 Patched in 1.38.3
  28. 2024-10-30 CVE-2024-9700 Authorization Bypass Through User-Controlled Key Affects <= 1.36.0 Patched in 1.36.1
  29. 2024-10-25 CVE-2024-10402 Missing Authorization Affects <= 1.35.1 Patched in 1.36.0
  30. 2024-10-16 CVE-2024-9352 Cross-Site Request Forgery (CSRF) Affects <= 1.35.1 Patched in 1.36.0
  31. 2024-10-16 CVE-2024-9351 Cross-Site Request Forgery (CSRF) Affects <= 1.35.1 Patched in 1.36.0
  32. 2024-09-09 CVE-2024-45625 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.34.0 Patched in 1.34.1
  33. 2024-08-01 CVE-2024-7389 Insufficiently Protected Credentials Affects <= 1.29.1 Patched in 1.29.2
  34. 2024-04-18 CVE-2024-31077 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.29.2 Patched in 1.29.3
  35. 2024-04-18 CVE-2024-31857 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.2 Patched in 1.15.4
  36. 2024-04-18 CVE-2024-28890 Unrestricted Upload of File with Dangerous Type Affects <= 1.28.1 Patched in 1.29.0
  37. 2024-04-08 CVE-2024-3053 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.29.2 Patched in 1.29.3
  38. 2024-03-29 CVE-2024-1794 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.29.0 Patched in 1.29.1
  39. 2024-03-25 CVE-2024-29777 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.29.0 Patched in 1.29.1
  40. 2023-11-14 CVE-2023-6133 Unrestricted Upload of File with Dangerous Type Affects <= 1.27.0 Patched in 1.28.0
  41. 2023-10-27 CVE-2023-5119 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.26.0 Patched in 1.27.0
  42. 2023-08-29 CVE-2023-4596 Unrestricted Upload of File with Dangerous Type Affects <= 1.24.6 Patched in 1.25.0
  43. 2023-07-10 CVE-2023-3134 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.24.1 Patched in 1.24.4
  44. 2023-06-12 CVE-2023-2010 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Affects <= 1.23.3 Patched in 1.24.1
  45. 2023-04-12 Missing Authorization Affects <= 1.22.1 Patched in 1.23.3
  46. 2023-04-12 Missing Authorization Affects <= 1.22.1 Patched in 1.23.3
  47. 2023-04-12 Missing Authorization Affects <= 1.22.1 Patched in 1.23.3
  48. 2021-10-20 CVE-2021-24700 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.15.4 Patched in 1.15.4
  49. 2021-07-14 CVE-2021-36821 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.14.12 Patched in 1.14.12
  50. 2021-03-01 CVE-2021-4417 Cross-Site Request Forgery (CSRF) Affects < 1.13.5 Patched in 1.13.5
  51. 2019-02-06 CVE-2019-9567 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.6 Patched in 1.6
  52. 2019-02-06 CVE-2019-9568 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.6 Patched in 1.6

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 33 languages, 9 at 90% or more

Dutch 100%
Spanish (Spain) 100%
Dutch (Formal) 98%
Spanish (Chile) 98%
Lao 94%
Persian 94%
Polish 93%
Chinese (China) 92%
Vietnamese 91%
Dutch (Belgium) 80%
Russian 80%
German 70%
Japanese 63%
French (France) 62%
German (Formal) 59%
Czech 56%
Spanish (Colombia) 55%
Portuguese (Brazil) 53%
Spanish (Ecuador) 53%
Spanish (Venezuela) 53%
Swedish 53%
English (Canada) 52%
Turkish 51%
Spanish (Argentina) 35%

Plus 9 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2025-06-04 500K+ → 600K+ up after 504 days in tier
  2. 2024-01-17 400K+ → 500K+ up after 1 days in tier
  3. 2024-01-16 500K+ → 400K+ down after 1 days in tier
  4. 2024-01-15 400K+ → 500K+ up after 340 days in tier
  5. 2023-02-09 300K+ → 400K+ up

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Forminator Forms – Contact Form, Payment Form & Custom Form Builder into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/forminator" width="480" height="300" style="border:0" loading="lazy" title="Forminator Forms – Contact Form, Payment Form & Custom Form Builder — Plugin Pulse"></iframe>
Preview card ↗

Forminator Forms – Contact Form, Payment Form & Custom Form Builder: 600K+ active installs, 4.8★ (2,112 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/forminator