
AeroLeads Contact Us Details Security & Risk Analysis
wordpress.org/plugins/aeroleads-contact-us-detailsAeroLeads Contact Us Details lets you add contact details in your sidebar as a widget. Simple yet effective.
Is AeroLeads Contact Us Details Safe to Use in 2026?
Generally Safe
Score 85/100AeroLeads Contact Us Details has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The aeroleads-contact-us-details v2.0.0 plugin exhibits a concerning security posture due to several identified weaknesses in its static analysis. A significant attack surface is exposed through two AJAX handlers, both of which lack proper authentication checks, making them prime targets for unauthorized access and execution of potentially harmful operations. Furthermore, the complete absence of nonce checks on these entry points exacerbates this risk, allowing for easier Cross-Site Request Forgery (CSRF) attacks.
The code analysis reveals a critical reliance on dangerous functions, specifically `create_function`, which is known to be a significant security risk. The plugin also performs a substantial number of SQL queries without any form of prepared statements, indicating a high likelihood of SQL injection vulnerabilities. Compounding these issues is the extremely poor output escaping, with only 2% of outputs being properly handled, leaving the plugin susceptible to Cross-Site Scripting (XSS) attacks. While the plugin has no recorded vulnerability history, this can be misleading; the absence of past CVEs does not guarantee current security. The combination of these code-level flaws presents a substantial risk.
In conclusion, despite a clean vulnerability history, the static analysis of aeroleads-contact-us-details v2.0.0 reveals critical security flaws. The unprotected AJAX handlers, lack of nonce and capability checks, use of `create_function`, unescaped output, and raw SQL queries create a highly vulnerable plugin. Users should exercise extreme caution and consider disabling or replacing this plugin until these significant security deficiencies are addressed.
Key Concerns
- AJAX handlers without auth checks
- Missing nonce checks on AJAX
- Dangerous function: create_function
- Raw SQL without prepared statements
- Poor output escaping
- No capability checks
AeroLeads Contact Us Details Security Vulnerabilities
AeroLeads Contact Us Details Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
AeroLeads Contact Us Details Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 15
Maintenance & Trust
AeroLeads Contact Us Details Maintenance & Trust
Maintenance Signals
Community Trust
AeroLeads Contact Us Details Alternatives
Contact Information Widget
contact-information-widget
Easily add a Contact Information Widget to your widgetable sidebar. With this plugin you can add a contact information.
CT Contact
ct-contact
Want to display your personal or business contact information? Then this awesome lil' contact widget plugin is for you.
CT Social
ct-social
An awesome social plugin, featuring all of the most popular social sites.
Callcontact
callcontact
Plugin dodający widget callconact do strony internetowej.
Simple Contact Us Form Widget
simple-contact-us-form-widget
Simple contact form (name, email, message) to be added to sidebars or footer area (as a widget), and/or any post or page (as a shortcode).
AeroLeads Contact Us Details Developer Profile
1 plugin · 70 total installs
How We Detect AeroLeads Contact Us Details
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aeroleads-contact-us-details/css/slick.css/wp-content/plugins/aeroleads-contact-us-details/css/alcud-admin.css/wp-content/plugins/aeroleads-contact-us-details/js/jquery_serializeJSON.js/wp-content/plugins/aeroleads-contact-us-details/js/slick.min.js/wp-content/plugins/aeroleads-contact-us-details/js/alcud-admin.jsjs/jquery_serializeJSON.jsjs/slick.min.jsjs/alcud-admin.jsaeroleads-contact-us-details/css/slick.css?ver=aeroleads-contact-us-details/css/alcud-admin.css?ver=aeroleads-contact-us-details/js/jquery_serializeJSON.js?ver=aeroleads-contact-us-details/js/slick.min.js?ver=aeroleads-contact-us-details/js/alcud-admin.js?ver=HTML / DOM Fingerprints
alcud-admin-display<!-- wp:paragraph --><!-- /wp:paragraph --><!-- wp:heading --><!-- /wp:heading -->+50 moredata-post-idalcud_admin_object