
All Post Contact Form Security & Risk Analysis
wordpress.org/plugins/allpost-contactformThis plugin adds confirmation and completion screens to any HTML form and sends submitted data via email.
Is All Post Contact Form Safe to Use in 2026?
Mostly Safe
Score 74/100All Post Contact Form is generally safe to use. 1 past CVE were resolved. Keep it updated.
The 'allpost-contactform' plugin, version 1.8.2, presents a mixed security posture. While the static analysis indicates a good practice in terms of its limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and SQL queries are 100% prepared, significant concerns remain. The 35% proper output escaping is a considerable weakness, suggesting potential for cross-site scripting (XSS) vulnerabilities where user-supplied data is rendered without adequate sanitization. Furthermore, the taint analysis revealing three flows with unsanitized paths, even without critical or high severity, warrants attention as it indicates potential entry points for malicious data manipulation.
The plugin's vulnerability history is highly concerning. It has a single known CVE, which is critical, and it is currently unpatched. This critical vulnerability is categorized as 'Unrestricted Upload of File with Dangerous Type,' which is a severe security flaw that could allow attackers to upload malicious files to the server. The fact that the last vulnerability was very recent (October 2024) and remains unpatched indicates a lack of timely security patching by the developer, posing an immediate and significant risk to users. While the plugin shows some positive security habits, the presence of an unpatched critical vulnerability and a high percentage of improperly escaped output significantly elevates the overall risk.
Key Concerns
- Unpatched critical CVE
- Low output escaping percentage
- Taint flows with unsanitized paths
All Post Contact Form Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
All Post Contact Form <= 1.8.0 - Unauthenticated Arbitrary File Upload
All Post Contact Form Code Analysis
Output Escaping
Data Flow Analysis
All Post Contact Form Attack Surface
WordPress Hooks 4
Maintenance & Trust
All Post Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
All Post Contact Form Alternatives
HTML Forms – Simple WordPress Forms Plugin
html-forms
A simpler, faster, and smarter WordPress forms plugin.
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress
wpzoom-forms
Drag & drop contact form builder for WordPress. Create contact forms, custom forms, email forms with spam protection. Works with Elementor, shortcodes
Contact Form Widget
new-contact-form-widget
Create contact forms with query table management. Simple setup, secure submissions, and easy customization for your site.
Quick Contact Form
quick-contact-form
An easy to set up, plug and play contact form with a huge range of options and styles. A beginner friendly WordPress contact form plugin.
modeloform
modeloform
Este plugin construye un formulario de correo electrónico con los campos habituales, listo para usar. Dirige los mensajes al mail de administración de …
All Post Contact Form Developer Profile
2 plugins · 20 total installs
How We Detect All Post Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/allpost-contactform/allpost-contactform.css/wp-content/plugins/allpost-contactform/allpost-contactform-admin.cssallpost-contactform.css?ver=allpost-contactform-admin.css?ver=HTML / DOM Fingerprints
rl_apcf_admin_menu<!-- The Plugin Name is : All Post Contact Form -->data-rlapcf-redirect-timedata-rlapcf-redirect-page<!-- The Plugin Name is : All Post Contact Form -->