
Anti-Spam URL Blocker for Contact Form Security & Risk Analysis
wordpress.org/plugins/anti-spam-url-blocker-for-contact-formShort Description: Securely prevents submission of URLs in Contact Form 7 forms.
Is Anti-Spam URL Blocker for Contact Form Safe to Use in 2026?
Generally Safe
Score 92/100Anti-Spam URL Blocker for Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "anti-spam-url-blocker-for-contact-form" v1.0.1 exhibits a strong security posture based on the provided static analysis. It demonstrates excellent adherence to secure coding practices by exclusively using prepared statements for SQL queries and ensuring all output is properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. The presence of a nonce check on one of its two AJAX handlers is a positive sign for protecting against CSRF attacks, although the lack of capability checks on any entry points is a notable weakness.
The taint analysis revealed no concerning flows, and the vulnerability history is clean, with no recorded CVEs. This suggests a well-maintained codebase and a lack of historically exploitable flaws. However, the complete absence of capability checks on both AJAX handlers represents a potential risk. If these handlers perform sensitive operations that should be restricted to authenticated users, they could be exploited by unauthenticated attackers.
In conclusion, this plugin appears to be robustly built with a focus on secure coding fundamentals. Its lack of known vulnerabilities and absence of risky code patterns are significant strengths. The primary area for concern is the missing capability checks on its AJAX handlers, which could lead to unauthorized actions if these handlers are not inherently safe for public access. Addressing this would further strengthen its overall security.
Key Concerns
- Missing capability checks on AJAX handlers
Anti-Spam URL Blocker for Contact Form Security Vulnerabilities
Anti-Spam URL Blocker for Contact Form Code Analysis
Anti-Spam URL Blocker for Contact Form Attack Surface
AJAX Handlers 2
WordPress Hooks 6
Maintenance & Trust
Anti-Spam URL Blocker for Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
Anti-Spam URL Blocker for Contact Form Alternatives
Custom Validation for CF7
custom-validation-for-cf7
Advanced validation for Contact Form 7: block URLs, validate phone and email, with admin settings.
Contact Form 7
contact-form-7
Just another contact form plugin. Simple but flexible.
WP Armour – Honeypot Anti Spam
honeypot
Fastest growing Anti Spam plugin. No API calls, subscriptions, captcha or puzzle. Full GDPR complaint. For comments, contact form, login, registration
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Contact Form 7 Captcha
contact-form-7-simple-recaptcha
Protect your Contact Form 7 forms with Google reCAPTCHA V2, Google reCAPTCHA V3, hCAPTCHA, or Cloudflare Turnstile.
Anti-Spam URL Blocker for Contact Form Developer Profile
1 plugin · 0 total installs
How We Detect Anti-Spam URL Blocker for Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/anti-spam-url-blocker-for-contact-form/assets/css/47b-cf-url-validator.css/wp-content/plugins/anti-spam-url-blocker-for-contact-form/assets/js/47b-cf-url-validator.js/wp-content/plugins/anti-spam-url-blocker-for-contact-form/assets/js/47b-cf-url-validator.jsanti-spam-url-blocker-for-contact-form/assets/css/47b-cf-url-validator.css?ver=anti-spam-url-blocker-for-contact-form/assets/js/47b-cf-url-validator.js?ver=HTML / DOM Fingerprints
b47CFURLValidator