Absence of Anti-CSRF Tokens

By: Pankaj Vatsyan | Asked: 10/30/2025
ForumsCategory: How-toAbsence of Anti-CSRF Tokens
Pankaj Vatsyan asked 1 week ago

Hello... We are using free version of Formidable Form plugin on our website.

 

Website:  https://cosecai.com/

 

in site audit report (scaned by https://hostedscan.com/), there is something that we caught up.

its says "No Anti-CSRF tokens were found in a HTML submission form". How we can add this.

URL:  https://cosecai.com/contact-us/

 

Anybody, can please help, How to achieve this.

 

 

1 Answers
Victor Font Staff answered 1 week ago

You're receiving a false positive. Formidable uses WordPress nonce. A WordPress nonce, short for "number used once," is a security token used to protect URLs and forms from malicious attacks, particularly Cross-Site Request Forgery (CSRF). While the name implies "used once," WordPress nonces actually have a limited "lifetime" during which they can be used for a specific action by a specific user.

Making the Best WordPress Plugin even better - Together

Take on bigger projects with confidence knowing you have access to an entire community of Formidable Experts and Professionals who have your back when the going gets tough. You got this!
Join the community
crossarrow-right