Plugin Pulse
← Pulse

Ninja Forms – The Contact Form Builder That Grows With You

by Kevin Stover · Forms

Also makes 4 other plugins · 610.1K+ installs across the portfolio →

The 100% beginner friendly WordPress form builder. Drag & drop form fields to build beautiful, professional contact forms in minutes.

How scoring works →
88 Health · A
Maintenance 100/100
Rating quality 85/100
Support 73/100

88 health vs 63 average across 1,679 Forms plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

92 / 100

Excellent listing optimization

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 88/100
Listing tuning 100/100
Support resolution 64/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

+1% vs prior 30d
9KDownloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

897.0K

now · peak 1.5M

941.4K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

Ninja Forms · #112 you WPForms · #9 Fluent Forms · #83 SureForms · #121

Rating trend

Star average over time · dips mark rough releases

4.4Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

1.6Kper 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

25

releases in the last 12 months

1mo ago

latest release · v3.14.9

39

tagged releases on record

Recent releases

3.14.9 · 1mo ago3.14.8 · 2mo ago3.14.7 · 2mo ago3.14.6 · 3mo ago3.14.5 · 3mo ago3.14.4 · 4mo ago3.14.3 · 4mo ago3.14.2 · 5mo ago3.14.1 · 7mo ago3.14.0 · 7mo ago3.13.4 · 7mo ago3.12.2.1 · 8mo ago3.11.1.1 · 8mo ago3.10.4.1 · 8mo ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v3.14 60%
v3.6 7.8%
v3.8 7.3%
Older / other versions 25%

Estimated active installs

The public count shows “600K+”. Our estimate pins where the real number sits.

tracked estimate
600K–700K ≈690K

Refined from the date this plugin crossed into its current band.

Install history · since 2015-03-10 · 1,487 observations

600KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

high confidence

Est. annual revenue

≈$640K range $150K–$2.8M

Est. acquisition value

≈$1.8M range $300K–$11M

A large install base, a clear pro tier and a steady trend. As reliable as an outside estimate gets. The range spans more than 10x because wp.org publishes install counts as broad bands, and conversion and price compound on top. Read the midpoint as an order of magnitude, not a valuation.

How we estimate this

Assumptions

  • Free → paid conversion. 0.5%–2% of active installs pay for the pro tier. Typical for freemium WordPress plugins; the real rate varies a lot by product.
  • Annual price per customer. $49–$199 a year, typical for Forms plugins rather than this plugin's own pricing.
  • Acquisition multiple. 2x–4x annual revenue, the going range for small WordPress-plugin businesses, the typical range for a steady plugin.
  • Install base. 600K–700K active installs, from our install estimate (wp.org only publishes the floor).

Inputs

Active installs
600K–700K
Category
Forms
Pro tier
detected (known freemium plugin with a public paid tier)
Download trend
steady (30d downloads flat vs prior 30d)
Reviews
1,395
Last updated
1 days ago

Revenue is installs × conversion × price; value is revenue × a typical acquisition multiple. Every factor is an assumption band, so the output is a wide range on purpose. If you're buying or selling, treat this as a starting point for due diligence.

Details

Version
3.15.1
Last updated
yesterday
Added
2011-12-21 · 14 yrs old
Requires WP
6.8
Tested up to
7.0.4
Requires PHP
7.4

Recent review vibe

read from the latest 12 reviews to 2026-06-11
Positive PraiseCompatibility

Reviewers keep praising Ninja Forms' fast, hands-on support and steady form-building experience, with a handful of low stars aimed only at the forced rating popup, not the plugin itself.

Recent reviews

All reviews on wp.org ↗
  1. rmwatts
    3mo ago

    There was a conflict between an older version of htmlpurifier included in the Excel Export plugin and a newer version in CiviCRM on our site that was creating nonstop bug reports. I submitted a ticket and got a very helpful response within a day and within two days the issue was resolved and the plugin is functioning without problem.

    Read on wp.org ↗
  2. Periklis Kakarakidis
    4mo ago

    Ninja forms seems to have a great UI for the creation of custom Forms and I personally love it!I would recommend it for everyone begginer and advanced wordpress user to try it.

    Read on wp.org ↗
  3. stargfxllc
    4mo ago

    The Ninja Forms team responds faster than most and actually gets the job done. They’re thorough, hands-on, and help resolve issues quickly. It saves a lot of time compared to the endless back-and-forth you get with other software companies. Instead of sending confusing emails, they jump in and help. Support like that keeps me coming back and confident using Ninja Forms on other websites. Cheers!

    Read on wp.org ↗
  4. blogginginnovation
    4mo ago

    Don’t like being forced to rate before I even know whether it works

    Read on wp.org ↗
  5. ju571n3
    4mo ago

    popup always This topic was modified 3 months ago by ju571n3.

    Read on wp.org ↗
  6. Fred
    5mo ago

    Great plugin, I’ve been using it with great satisfaction for several years now.The support is fantastic; they respond quickly, reliably, and are very competent.Thanks and keep up the good work!

    Read on wp.org ↗
  7. zonaisgood
    5mo ago

    popup

    Read on wp.org ↗
  8. bobjgarrett
    5mo ago

    We have been using this for a while and found it to be excellent. Recently had a problem which their support quickly proposed a solution for that related to how another plugin was set up.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. Version 3.14.10 Bug Fixes: fix anchor tag URLs breaking when merge tags are used as querystrings in HTML fields fix date field required validation not triggering for Date & Time mode fix {other:date} merge tag reporting dates in UTC ins 3.14.10
  2. Version 3.14.9 Bug Fixes: restore visibility of “Almost there…” heading in new-form drawer add descender allowance for typed signature fonts in PDF Security Enhancements: protect against unauthorized multisite data deletion protect aga 3.14.9
  3. Version 3.14.8 Bug Fixes: fix merge tag picker falsely triggering for calculation tags with slash in name fix phone field truncating last digit when browser autofill includes country code fix PHP warning for array offset on null in Mod 3.14.8
  4. Version 3.14.7 Bug Fixes: fix date field “default to current date” displaying wrong date with conditional logic fix date/date-time field value corruption when editing via submissions backend fix checkbox fields not being redacted from 3.14.7
  5. Version 3.14.6 Bug Fixes: fix PHP warnings when retriggering emails from submissions page fix bulk export returning no results when selecting a single day 3.14.6
  6. Version 3.14.5 Bug Fixes: fix Rich Text Editor content displaying as raw HTML in submissions modal fix HTML entity decoding in Rich Text Editor fields fix Quill Rich Text Editor inline text alignment not being preserved fix unordered l 3.14.5

Known vulnerabilities

via Wordfence Intelligence

78 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-07-23 CVE-2026-15663 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.14.9 Patched in 3.14.10
  2. 2026-06-30 CVE-2026-1239 Missing Authorization Affects <= 3.14.1 Patched in 3.14.2
  3. 2026-03-27 CVE-2026-1307 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.14.1 Patched in 3.14.2
  4. 2026-02-09 CVE-2026-2268 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.14.0 Patched in 3.14.1
  5. 2025-12-16 CVE-2025-11924 Authorization Bypass Through User-Controlled Key Affects <= 3.13.2 Patched in 3.13.3
  6. 2025-12-12 CVE-2025-14072 Missing Authorization Affects <= 3.13.2 Patched in 3.13.3
  7. 2025-09-26 CVE-2025-10499 Cross-Site Request Forgery (CSRF) Affects <= 3.12.0 Patched in 3.12.1
  8. 2025-09-26 CVE-2025-10498 Cross-Site Request Forgery (CSRF) Affects <= 3.12.0 Patched in 3.12.1
  9. 2025-08-28 CVE-2025-9083 Deserialization of Untrusted Data Affects <= 3.11.0 Patched in 3.11.1
  10. 2025-06-26 CVE-2025-5398 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.10.2.1 Patched in 3.10.2.2
  11. 2025-04-28 CVE-2025-2561 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.10.0 Patched in 3.10.1
  12. 2025-04-28 CVE-2025-2560 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.10.0 Patched in 3.10.1
  13. 2025-04-28 CVE-2025-2524 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.10.0 Patched in 3.10.1
  14. 2025-01-29 CVE-2024-13470 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.8.24 Patched in 3.8.25
  15. 2024-12-28 CVE-2024-12238 Improper Control of Generation of Code ('Code Injection') Affects <= 3.8.22 Patched in 3.8.23
  16. 2024-12-11 CVE-2024-11052 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.8.19 Patched in 3.8.20
  17. 2024-10-28 CVE-2024-50515 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.8.17 Patched in 3.8.18
  18. 2024-10-28 CVE-2024-50514 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.8.17 Patched in 3.8.18
  19. 2024-09-24 CVE-2024-3866 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.8.15 Patched in 3.8.16
  20. 2024-08-28 CVE-2024-43999 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.8.11 Patched in 3.8.12
  21. 2024-08-12 CVE-2024-7354 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects 3.8.6 - 3.8.10 Patched in 3.8.11
  22. 2024-07-24 CVE-2024-39628 Cross-Site Request Forgery (CSRF) Affects <= 3.8.6 Patched in 3.8.7
  23. 2024-07-04 CVE-2024-37934 Missing Authorization Affects <= 3.8.4 Patched in 3.8.5
  24. 2024-04-08 CVE-2024-26019 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.8.0 Patched in 3.8.1
  25. 2024-04-08 CVE-2024-29220 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.8.0 Patched in 3.8.1
  26. 2024-03-28 CVE-2024-2113 Cross-Site Request Forgery (CSRF) Affects <= 3.8.0 Patched in 3.8.1
  27. 2024-03-28 CVE-2024-2108 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.8.0 Patched in 3.8.1
  28. 2024-02-01 CVE-2024-0685 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.7.1 Patched in 3.7.2
  29. 2023-10-16 CVE-2023-5530 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.33 Patched in 3.6.34
  30. 2023-08-07 CVE-2023-4109 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.25 Patched in 3.6.26
  31. 2023-07-25 CVE-2023-37979 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.25 Patched in 3.6.26
  32. 2023-07-25 CVE-2023-38386 Missing Authorization Affects <= 3.6.25 Patched in 3.6.26
  33. 2023-07-25 CVE-2023-38393 Missing Authorization Affects <= 3.6.25 Patched in 3.6.26
  34. 2023-07-07 CVE-2023-35909 Uncontrolled Resource Consumption Affects <= 3.6.25 Patched in 3.6.26
  35. 2023-06-22 CVE-2023-36505 External Control of File Name or Path Affects <= 3.6.24 Patched in 3.6.25
  36. 2023-04-24 CVE-2023-1835 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.21 Patched in 3.6.22
  37. 2022-09-05 CVE-2022-2903 Deserialization of Untrusted Data Affects <= 3.6.12 Patched in 3.6.13
  38. 2022-06-15 Improper Control of Generation of Code ('Code Injection') Affects <= 3.0.34.1 Patched in 3.0.34.2
  39. 2022-06-13 CVE-2021-25056 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.9 Patched in 3.6.10
  40. 2022-06-10 CVE-2021-25066 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.10 Patched in 3.6.11
  41. 2022-06-07 CVE-2021-36827 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.6.9 Patched in 3.6.10
  42. 2022-06-07 Cross-Site Request Forgery (CSRF) Affects <= 3.6.9 Patched in 3.6.10
  43. 2022-03-22 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 3.6.7 Patched in 3.6.8
  44. 2021-10-26 CVE-2021-24889 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 3.6.4 Patched in 3.6.4
  45. 2021-09-27 CVE-2021-24381 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.5.8.2 Patched in 3.5.8.2
  46. 2021-09-22 CVE-2021-34647 Incorrect Authorization Affects <= 3.5.7 Patched in 3.5.8
  47. 2021-09-22 CVE-2021-34648 Incorrect Authorization Affects <= 3.5.7 Patched in 3.5.8
  48. 2021-02-16 CVE-2021-24165 URL Redirection to Untrusted Site ('Open Redirect') Affects < 3.4.34 Patched in 3.4.34
  49. 2021-02-16 CVE-2021-24163 Exposure of Sensitive Information to an Unauthorized Actor Affects < 3.4.34 Patched in 3.4.34
  50. 2021-02-16 CVE-2021-24164 Exposure of Sensitive Information to an Unauthorized Actor Affects < 3.4.34.1 Patched in 3.4.34.1
  51. 2021-02-16 CVE-2021-24166 Cross-Site Request Forgery (CSRF) Affects < 3.4.34 Patched in 3.4.34
  52. 2020-09-22 CVE-2020-36175 Improper Input Validation Affects <= 3.4.27 Patched in 3.4.27.1
  53. 2020-09-22 CVE-2020-36174 Cross-Site Request Forgery (CSRF) Affects <= 3.4.27 Patched in 3.4.27.1
  54. 2020-09-20 CVE-2020-36173 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 3.4.27.1 Patched in 3.4.28
  55. 2020-04-28 CVE-2020-12462 Cross-Site Request Forgery (CSRF) Affects < 3.4.24.2 Patched in 3.4.24.2
  56. 2020-02-03 CVE-2020-8594 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.4.23 Patched in 3.4.23
  57. 2019-01-07 CVE-2019-15025 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 3.3.21.1 Patched in 3.3.21.2
  58. 2018-12-01 CVE-2018-19796 URL Redirection to Untrusted Site ('Open Redirect') Affects <= 3.3.19 Patched in 3.3.19.1
  59. 2018-11-15 CVE-2018-19287 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.3.18 Patched in 3.3.18
  60. 2018-08-27 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.3.14 Patched in 3.3.14
  61. 2018-08-19 CVE-2018-16308 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 3.3.13 Patched in 3.3.14
  62. 2018-07-06 CVE-2018-20981 Improper Input Validation Affects <= 3.3.8 Patched in 3.3.9
  63. 2018-02-26 CVE-2018-20980 Improper Input Validation Affects < 3.2.15 Patched in 3.2.15
  64. 2018-02-20 CVE-2018-7280 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 3.2.14 Patched in 3.2.14
  65. 2017-04-17 Improper Control of Generation of Code ('Code Injection') Affects <= 3.0.31 Patched in 3.0.32
  66. 2017-03-07 CVE-2017-18574 Improper Input Validation Affects < 3.0.31 Patched in 3.0.31
  67. 2016-08-16 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 2.9.55.2 Patched in 2.9.55.2
  68. 2016-07-19 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.9.52 Patched in 2.9.52
  69. 2016-05-13 CVE-2016-1209 Improper Input Validation Affects 2.9.36 - 2.9.42 Patched in 2.9.42.1
  70. 2016-05-05 CVE-2016-1209 Unrestricted Upload of File with Dangerous Type Affects 2.9.36 - 2.9.42 Patched in 2.9.42.1
  71. 2015-12-08 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.9.28 Patched in 2.9.29
  72. 2015-09-30 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Affects <= 2.9.27 Patched in 2.9.28
  73. 2015-08-04 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.9.21 Patched in 2.9.22
  74. 2015-06-05 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.9.18 Patched in 2.9.19
  75. 2015-04-20 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.9.11 Patched in 2.9.11
  76. 2014-12-02 CVE-2014-9688 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.8.10 Patched in 2.8.10
  77. 2014-11-20 CVE-2015-2220 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects < 2.8.9 Patched in 2.8.9
  78. 2014-11-06 CVE-2014-8815 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.8.6 Patched in 2.8.7

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 120 languages, 27 at 90% or more

Arabic 100%
Basque 100%
Dutch 100%
Dutch (Belgium) 100%
Dutch (Formal) 100%
English (UK) 100%
Esperanto 100%
French (France) 100%
German 100%
German (Formal) 100%
German (Switzerland) 100%
German (Switzerland) Informal 100%
Korean 100%
Lao 100%
Persian 100%
Polish 100%
Spanish (Chile) 100%
Spanish (Spain) 100%
Spanish (Costa Rica) 99%
Czech 98%
Spanish (Venezuela) 95%
Swedish 95%
English (South Africa) 94%
Spanish (Colombia) 94%

Plus 96 more locales with partial translations.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2025-08-16 700K+ → 600K+ down after 4 days in tier
  2. 2025-08-12 600K+ → 700K+ up after 3 days in tier
  3. 2025-08-09 700K+ → 600K+ down after 1 days in tier
  4. 2025-08-08 600K+ → 700K+ up after 3 days in tier
  5. 2025-08-05 700K+ → 600K+ down after 295 days in tier
  6. 2024-10-14 800K+ → 700K+ down after 445 days in tier
  7. 2023-07-27 900K+ → 800K+ down after 2 days in tier
  8. 2023-07-25 800K+ → 900K+ up after 1 days in tier

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for Ninja Forms – The Contact Form Builder That Grows With You into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/ninja-forms" width="480" height="300" style="border:0" loading="lazy" title="Ninja Forms – The Contact Form Builder That Grows With You — Plugin Pulse"></iframe>
Preview card ↗

Ninja Forms – The Contact Form Builder That Grows With You: 600K+ active installs, 4.4★ (1,395 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/ninja-forms