
Ajax Contact Form Security & Risk Analysis
wordpress.org/plugins/ajax-contact-formThis plugin sends mail using ajax and gather email list, have options page, custom css and form design usability.
Is Ajax Contact Form Safe to Use in 2026?
Generally Safe
Score 85/100Ajax Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'ajax-contact-form' v1.0 plugin exhibits a concerning security posture due to a significant number of critical vulnerabilities identified in static and taint analysis. While there is no recorded vulnerability history, suggesting a lack of known public exploits, the internal code analysis reveals substantial risks. The presence of two AJAX handlers without authentication checks creates a direct attack surface for unauthorized actions. Furthermore, the taint analysis indicating 5 flows with unsanitized paths and a critical severity for all of them is highly alarming, pointing to potential for arbitrary code execution or data compromise. The complete absence of prepared statements for SQL queries and proper output escaping, with 100% of SQL queries and outputs being vulnerable, dramatically amplifies these risks, making the plugin highly susceptible to SQL injection and cross-site scripting (XSS) attacks. The lack of any capability or nonce checks further exacerbates the insecurity.
Key Concerns
- AJAX handlers without auth checks
- Critical taint flow with unsanitized paths
- Raw SQL queries without prepared statements
- Output escaping is not properly handled
- Missing nonce checks on AJAX handlers
- Missing capability checks on AJAX handlers
Ajax Contact Form Security Vulnerabilities
Ajax Contact Form Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Ajax Contact Form Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Ajax Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
Ajax Contact Form Alternatives
فرم ساز فرم افزار
formafzar
ابزاری آسان برای ساخت فرمهای آنلاین قدرتمند بصورت حرفهای، به آسانی و کمتر از چند دقیقه فرم خودتون رو بسازید و به اشتراک بگذارید
WPCF
wpcf
WPCF is a simple WordPress contact form. You can easily add this in your page,post anywhere with shortcode.
Contact Form Migrator from Pirate Forms to Formidable
formidable-import-pirate-forms
Migrate your Pirate Forms contact forms automatically to Formidable Forms.
PeproDev CF7 SMS Notifier
pepro-cf7-sms-notifier
Send notifications to User and Admins upon Contact Form 7 Submission
Ajax Contact Form Developer Profile
1 plugin · 20 total installs
How We Detect Ajax Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ajax-contact-form/style.css/wp-content/plugins/ajax-contact-form/ajaxcf.jsajax-contact-form/style.css?ver=ajaxcf.js?ver=HTML / DOM Fingerprints
the_ajax_scriptajax_contact_form