
A Capture Contact Form (and tab) by AWebVoice.com Security & Risk Analysis
wordpress.org/plugins/a-lead-capture-contact-form-and-tab-button-by-awebvoicecomGet a contact form and a contact button. Capture your visitors and turn them into customers!
Is A Capture Contact Form (and tab) by AWebVoice.com Safe to Use in 2026?
Generally Safe
Score 85/100A Capture Contact Form (and tab) by AWebVoice.com has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "a-lead-capture-contact-form-and-tab-button-by-awebvoicecom" version 3.0 exhibits a concerning security posture due to several critical code analysis findings. While the plugin boasts a zero attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events, and all SQL queries are prepared, this masks significant underlying risks. The presence of the `unserialize` function, coupled with two taint flows with unsanitized paths, strongly suggests potential for deserialization vulnerabilities. This is further exacerbated by the fact that 100% of its output is not properly escaped, creating a high risk of cross-site scripting (XSS) attacks if any data processed by the plugin is reflected in the output without sanitization. The absence of any known CVEs is a positive, but it does not negate the clear and present dangers identified within the code itself. The plugin's strengths lie in its limited attack surface and secure SQL handling, but these are overshadowed by the critical risks associated with unserialization and unescaped output. Aggressive remediation is required to address these vulnerabilities.
Key Concerns
- Dangerous function 'unserialize' found
- Taint flows with unsanitized paths (High severity)
- Output escaping not properly implemented
- No nonce checks
- No capability checks
A Capture Contact Form (and tab) by AWebVoice.com Security Vulnerabilities
A Capture Contact Form (and tab) by AWebVoice.com Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
A Capture Contact Form (and tab) by AWebVoice.com Attack Surface
WordPress Hooks 4
Maintenance & Trust
A Capture Contact Form (and tab) by AWebVoice.com Maintenance & Trust
Maintenance Signals
Community Trust
A Capture Contact Form (and tab) by AWebVoice.com Alternatives
Custom Contact Forms
custom-contact-forms
Build beautiful custom forms and manage submissions the WordPress way. View live previews of your forms while you build them.
Corymbus Forms
corymbus-forms
Corymbus Forms provides the [corymbus-forms] shortcode which lets you easily embed in your website a web form/page published from the Corymbus CRM.
First Contact Form
first-contact-form
Manage multiple forms in a few clicks away, and way more flexible and User Friendly than other form plugins.
RackForms Express Web Form Builder
rackforms-express
RackForms Express For WordPress is a FREE and UNLIMITED web form builder.
WP InfusionSoft
wp-infusionsoft
WP Infusionsoft is a plugin for handling web forms created by the popular email marketing site InfusionSoft.
A Capture Contact Form (and tab) by AWebVoice.com Developer Profile
1 plugin · 10 total installs
How We Detect A Capture Contact Form (and tab) by AWebVoice.com
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
id="awebvoice_form"id="awebvoice_frame"name="awebvoice_data"id="awebvoice_data"var _aweb =var cms =<iframe src="http://www.awebvoice.com/wordpress?l=jQuery('#awebvoice_data').val(e.data);jQuery("#awebvoice_form").submit();