
MA Bootstrap Contact Form Security & Risk Analysis
wordpress.org/plugins/bootstrap-contact-formBootstrap Contact Form is a wordpress plugin that easily creates contact forms in Swedish and English, styled by Bootstrap.
Is MA Bootstrap Contact Form Safe to Use in 2026?
Generally Safe
Score 85/100MA Bootstrap Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'bootstrap-contact-form' v1.4 plugin exhibits a generally positive security posture due to the absence of known vulnerabilities and a lack of dangerous functions or direct SQL queries. The static analysis indicates a relatively small attack surface consisting of two shortcodes, with no identified AJAX handlers or REST API routes requiring immediate attention. Furthermore, all SQL queries utilize prepared statements, which is a strong security practice.
However, the analysis does reveal some areas of concern. A significant portion of output (43%) is not properly escaped, creating a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is rendered directly. The taint analysis, while not flagging critical or high-severity issues, did identify four flows with unsanitized paths, suggesting that data might be processed in a way that could be exploited if an attacker can control the input to these paths. The complete lack of nonce checks and capability checks, even on entry points that don't require authentication, is also a notable weakness. This means that even simple shortcodes, if they involve any form of data processing or interaction, could be triggered by unauthenticated users with unpredictable consequences.
In conclusion, while the plugin benefits from a clean vulnerability history and sound SQL practices, the unescaped output and unsanitized paths, coupled with the absence of any authorization or nonce checks, present a considerable risk. These weaknesses could be exploited to inject malicious scripts or manipulate plugin behavior, especially if the shortcodes handle any user-provided data. Addressing the output escaping and implementing appropriate checks would significantly improve its security.
Key Concerns
- Unescaped output detected
- Unsanitized paths in taint analysis
- No nonce checks
- No capability checks
MA Bootstrap Contact Form Security Vulnerabilities
MA Bootstrap Contact Form Code Analysis
Output Escaping
Data Flow Analysis
MA Bootstrap Contact Form Attack Surface
Shortcodes 2
WordPress Hooks 1
Maintenance & Trust
MA Bootstrap Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
MA Bootstrap Contact Form Alternatives
Bootstrap for Contact Form 7
bootstrap-for-contact-form-7
This plugin modifies the output of the popular Contact Form 7 plugin to be styled in compliance with themes using the Bootstrap CSS framework.
Contact Form Clean and Simple
clean-and-simple-contact-form-by-meg-nicholas
A clean and simple contact form with flexible CSS framework support.
Lana Contact Form
lana-contact-form
Easy to use contact form with captcha
WPxon Ajax Contact Form
wpxon-ajax-contact-form
Ajax contact form is a simple and clean deisnged contact form.
Themeable Contact Form
themeable-contact-form
A simple contact form plugin that allows you to customize the template to match your theme
MA Bootstrap Contact Form Developer Profile
1 plugin · 10 total installs
How We Detect MA Bootstrap Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bootstrap-contact-form/includes/admin.php/wp-content/plugins/bootstrap-contact-form/includes/core.phpHTML / DOM Fingerprints
[bootstrapcontactform_swedish][bootstrapcontactform_english]