Forminator Forms – Contact Form, Payment Form & Custom Form Builder
by WPMU DEV - Your All-in-One WordPress Platform · Forms
Also makes 8 other plugins · 2.4M+ installs across the portfolio →
Best WordPress form builder plugin. Create contact forms, payment forms & order forms with 1000+ integrations.
95 health vs 63 average across 1,678 Forms plugins
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Excellent listing optimization
Well tuned across the board
Daily downloads
Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
957.9K
now · peak 982.0K
Directory rank vs rivals
wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you
Rating trend
Star average over time · dips mark rough releases
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Release cadence
Actively maintainedHow often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.
23
releases in the last 12 months
2mo ago
latest release · v1.55.1
129
tagged releases on record
Recent releases
What its installed base runs
via wordpress.orgShare of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.
Estimated active installs
The public count shows “600K+”. Our estimate pins where the real number sits.
Refined from the date this plugin crossed into its current band.
Install history · since 2018-09-16 · 1,465 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. The recent download trend is too spiky to read.
Details
Recent review vibe
read from the latest 12 reviews to 2026-07-20Reviewers are consistently happy with Forminator's free feature set, ease of use and support, with only a passing request for submission-limit controls.
Recent reviews
All reviews on wp.org ↗- ★★★★★ techmesa1mo ago
This plug in works great and and even lets you embed stripe payments on your forms – for free. Supports test and paid modes – PLUS conditions for when any part of the form is shown. You can even add different products and different pricces and show them based on conditions. Far better than I expected and you cant find these features in a free plug in anywhere.
Read on wp.org ↗ - ★★★★★ didier594501mo ago
Very good support, even when it’s complicated!
Read on wp.org ↗ - ★★★★★ Pamelita1mo ago
Don´t you just love it when an plugin actually does what it says? And stays solid, up-to-date while easy to use. Excellent plugin.
Read on wp.org ↗ - ★★★★★ chief5012mo ago
Great product! Fantastic free tool to manage forms and payments for my non-profit.
Read on wp.org ↗ - ★★★★★ 2ndchanceapartments2mo ago
I am using for own my [redacted] website. This topic was modified 1 week, 3 days ago by Steven Stern (sterndata). Reason: removed link to site
Read on wp.org ↗ - ★★★★★ stincpao2mo ago
I’ve used it for an online test with custom calculations for the result and custom results pages.
Read on wp.org ↗ - ★★★★★ jariapesland2mo ago
I’ve used Forminator on multiple clients websites. I’ve never had an issue with it. I’ve also used it for fun quizzes on clients websites and everything works great.
Read on wp.org ↗ - ★★★★★ sicman2mo ago
Vraiment top !
Read on wp.org ↗
Latest updates
via wp.org changelogRecent releases and news for this plugin
- 2026-08-18 Version 1.57.1 Fix: Security issue affecting Multisite site registration (props: Jakub Herman) 1.57.1
- 2026-08-18 Version 1.57.0.8 Fix: Security issue affecting payment processing (props: Jakub Herman) 1.57.0.8
- 2026-08-18 Version 1.57.0.7 Fix: Privilege escalation vulnerability 1.57.0.7
- 2026-08-18 Version 1.57.0.6 Fix: Vulnerability – PHP Object Injection 1.57.0.6
- 2026-08-18 Version 1.57.0.5 Fix: Security improvements on Hub-Connector (props: Jakub Herman) 1.57.0.5
- 2026-08-18 Version 1.57.0.4 Fix: Cross-Site Scripting (XSS) vulnerability 1.57.0.4
Known vulnerabilities
via Wordfence Intelligence52 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.
- 2026-08-24 CVE-2026-18328 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.57.0 Patched in 1.57.0.1
- 2026-08-24 CVE-2026-18323 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.57.0.2 Patched in 1.57.0.3
- Critical · 9.8 Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration ↗2026-08-17 CVE-2026-15748 Unrestricted Upload of File with Dangerous Type Affects <= 1.56.1 Patched in 1.56.2
- 2026-08-15 CVE-2026-12998 Authorization Bypass Through User-Controlled Key Affects <= 1.55.0.2 Patched in 1.55.1
- 2026-08-05 CVE-2026-18325 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.56.1 Patched in 1.56.2
- 2026-08-03 CVE-2026-28143 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.56.0 Patched in 1.56.1
- 2026-07-08 CVE-2026-57815 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 1.55.0.2 Patched in 1.55.1
- 2026-07-08 CVE-2026-57814 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.55.0.1 Patched in 1.55.0.2
- 2026-06-24 CVE-2026-56071 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.53.1 Patched in 1.53.2
- 2026-05-04 CVE-2026-5192 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Affects <= 1.52.1 Patched in 1.52.2
- 2026-05-04 CVE-2026-2729 Authorization Bypass Through User-Controlled Key Affects <= 1.52.0 Patched in 1.52.1
- Medium · 5.3 Forminator <= 1.50.2 - Missing Authorization ↗
- 2026-02-16 CVE-2026-2002 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.50.2 Patched in 1.50.3
- 2025-07-17 CVE-2025-7638 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.45.0 Patched in 1.45.1
- 2025-06-04 CVE-2025-5341 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.44.1 Patched in 1.44.2
- Medium · 6.4 Forminator <= 1.42.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'limit' ↗2025-04-16 CVE-2025-3487 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.42.0 Patched in 1.42.1
- Medium · 5.3 Forminator <= 1.42.0 - Order Replay Vulnerability ↗2025-04-16 CVE-2025-3479 Improper Validation of Integrity Check Value Affects <= 1.42.0 Patched in 1.42.1
- 2025-02-26 CVE-2025-0469 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 1.39.2 Patched in 1.39.3
- 2025-01-30 CVE-2025-0470 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.38.2 Patched in 1.38.3
- 2025-01-24 CVE-2024-7052 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.38.2 Patched in 1.38.3
- 2024-10-30 CVE-2024-9700 Authorization Bypass Through User-Controlled Key Affects <= 1.36.0 Patched in 1.36.1
- Medium · 6.1 Forminator Forms – Contact Form, Payment Form & Custom Form Builder <= 1.34.0 - Reflected Cross-Site Scripting ↗2024-09-09 CVE-2024-45625 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.34.0 Patched in 1.34.1
- 2024-04-18 CVE-2024-31077 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.29.2 Patched in 1.29.3
- 2024-04-18 CVE-2024-31857 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.15.2 Patched in 1.15.4
- 2024-04-18 CVE-2024-28890 Unrestricted Upload of File with Dangerous Type Affects <= 1.28.1 Patched in 1.29.0
- 2024-04-08 CVE-2024-3053 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.29.2 Patched in 1.29.3
- 2024-03-29 CVE-2024-1794 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.29.0 Patched in 1.29.1
- 2024-03-25 CVE-2024-29777 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.29.0 Patched in 1.29.1
- 2023-11-14 CVE-2023-6133 Unrestricted Upload of File with Dangerous Type Affects <= 1.27.0 Patched in 1.28.0
- 2023-10-27 CVE-2023-5119 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.26.0 Patched in 1.27.0
- 2023-08-29 CVE-2023-4596 Unrestricted Upload of File with Dangerous Type Affects <= 1.24.6 Patched in 1.25.0
- 2023-07-10 CVE-2023-3134 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.24.1 Patched in 1.24.4
- 2023-06-12 CVE-2023-2010 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Affects <= 1.23.3 Patched in 1.24.1
- Medium · 4.3 Forminator <= 1.22.1 - Missing Authorization on 'load_hcaptcha_preview' AJAX function ↗2023-04-12 Missing Authorization Affects <= 1.22.1 Patched in 1.23.3
- Medium · 4.3 Forminator <= 1.22.1 - Missing Authorization on 'load_recaptcha_preview' AJAX function ↗2023-04-12 Missing Authorization Affects <= 1.22.1 Patched in 1.23.3
- Medium · 4.3 Forminator <= 1.22.1 - Missing Authorization on 'hubspot_support_request' AJAX function ↗2023-04-12 Missing Authorization Affects <= 1.22.1 Patched in 1.23.3
- 2021-10-20 CVE-2021-24700 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.15.4 Patched in 1.15.4
- 2021-07-14 CVE-2021-36821 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.14.12 Patched in 1.14.12
- Medium · 6.1 Forminator Plugin <= 1.5.4 - Cross-Site Scripting ↗2019-02-06 CVE-2019-9567 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 1.6 Patched in 1.6
- Medium · 6.5 Forminator Plugin <= 1.5.3.1 - SQL Injection ↗2019-02-06 CVE-2019-9568 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 1.6 Patched in 1.6
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Behavioral tests
via WP HiveAutomated install-time checks, tested on PHP 8.1.12 · WP 7.0
Languages
via translate.wordpress.orgTranslated into 33 languages, 9 at 90% or more
Plus 9 more locales with partial translations.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
- 2025-06-04 500K+ → 600K+ up after 504 days in tier
- 2024-01-17 400K+ → 500K+ up after 1 days in tier
- 2024-01-16 500K+ → 400K+ down after 1 days in tier
- 2024-01-15 400K+ → 500K+ up after 340 days in tier
- 2023-02-09 300K+ → 400K+ up
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
Formidable Forms – WordPress Form Builder for Contact Forms, Calculators, Quizzes & More 300K+ installs · 4.8★ · 4 shared tags A -
Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder 20K+ installs · 4.2★ · 4 shared tags A -
Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms 20K+ installs · 4.4★ · 4 shared tags A -
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More 5M+ installs · 4.8★ · 3 shared tags A
-
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder 700K+ installs · 4.8★ · 3 shared tags A -
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz 500K+ installs · 4.8★ · 3 shared tags A
Embed this report card
Drop a live Pulse card for Forminator Forms – Contact Form, Payment Form & Custom Form Builder into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/forminator" width="480" height="300" style="border:0" loading="lazy" title="Forminator Forms – Contact Form, Payment Form & Custom Form Builder — Plugin Pulse"></iframe> Forminator Forms – Contact Form, Payment Form & Custom Form Builder: 600K+ active installs, 4.8★ (2,112 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/forminator