All Post Contact Form Security & Risk Analysis

wordpress.org/plugins/allpost-contactform

This plugin adds confirmation and completion screens to any HTML form and sends submitted data via email.

10 active installs v1.8.2 PHP 8.0+ WP 4.7.3+ Updated Unknown
contact-formemail-forminquiry-form
74
B · Generally Safe
CVEs total1
Unpatched1
Last CVEOct 30, 2024
Safety Verdict

Is All Post Contact Form Safe to Use in 2026?

Mostly Safe

Score 74/100

All Post Contact Form is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Oct 30, 2024
Risk Assessment

The 'allpost-contactform' plugin, version 1.8.2, presents a mixed security posture. While the static analysis indicates a good practice in terms of its limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and SQL queries are 100% prepared, significant concerns remain. The 35% proper output escaping is a considerable weakness, suggesting potential for cross-site scripting (XSS) vulnerabilities where user-supplied data is rendered without adequate sanitization. Furthermore, the taint analysis revealing three flows with unsanitized paths, even without critical or high severity, warrants attention as it indicates potential entry points for malicious data manipulation.

The plugin's vulnerability history is highly concerning. It has a single known CVE, which is critical, and it is currently unpatched. This critical vulnerability is categorized as 'Unrestricted Upload of File with Dangerous Type,' which is a severe security flaw that could allow attackers to upload malicious files to the server. The fact that the last vulnerability was very recent (October 2024) and remains unpatched indicates a lack of timely security patching by the developer, posing an immediate and significant risk to users. While the plugin shows some positive security habits, the presence of an unpatched critical vulnerability and a high percentage of improperly escaped output significantly elevates the overall risk.

Key Concerns

  • Unpatched critical CVE
  • Low output escaping percentage
  • Taint flows with unsanitized paths
Vulnerabilities
1

All Post Contact Form Security Vulnerabilities

CVEs by Year

1 CVE in 2024 · unpatched
2024
Patched Has unpatched

Severity Breakdown

Critical
1

1 total CVE

CVE-2024-50523critical · 9.8Unrestricted Upload of File with Dangerous Type

All Post Contact Form <= 1.8.0 - Unauthenticated Arbitrary File Upload

Oct 30, 2024Unpatched
Code Analysis
Analyzed Mar 16, 2026

All Post Contact Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
112
59 escaped
Nonce Checks
2
Capability Checks
0
File Operations
13
External Requests
0
Bundled Libraries
0

Output Escaping

35% escaped171 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
<allpost-contactform-sub12_uploadAttachment> (allpost-contactform-sub12_uploadAttachment.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

All Post Contact Form Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initallpost-contactform.php:74
actionadmin_menuallpost-contactform.php:75
actionwp_enqueue_scriptsallpost-contactform.php:76
filterusing_the_pluginallpost-contactform.php:78
Maintenance & Trust

All Post Contact Form Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version8.0
Downloads7K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

All Post Contact Form Developer Profile

RainbowLink Inc.

2 plugins · 20 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect All Post Contact Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/allpost-contactform/allpost-contactform.css/wp-content/plugins/allpost-contactform/allpost-contactform-admin.css
Version Parameters
allpost-contactform.css?ver=allpost-contactform-admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
rl_apcf_admin_menu
HTML Comments
<!-- The Plugin Name is : All Post Contact Form -->
Data Attributes
data-rlapcf-redirect-timedata-rlapcf-redirect-page
Shortcode Output
<!-- The Plugin Name is : All Post Contact Form -->
FAQ

Frequently Asked Questions about All Post Contact Form