
CB Contact Form Security & Risk Analysis
wordpress.org/plugins/cb-contact-formA very simple contact form plugin for Wordpress
Is CB Contact Form Safe to Use in 2026?
Generally Safe
Score 85/100CB Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cb-contact-form" plugin version 1.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements exclusively for SQL queries, and having no recorded vulnerabilities or CVEs. This suggests a generally stable and secure codebase in terms of common attack vectors like SQL injection. However, significant concerns arise from its attack surface, particularly the presence of two AJAX handlers that lack authentication checks. This leaves the plugin vulnerable to unauthorized execution of its backend functionalities, potentially allowing attackers to perform actions as if they were authenticated users.
The static analysis reveals a limited but crucial weakness in output escaping, with only 23% of outputs being properly escaped. This opens the door to potential Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the plugin's output and executed in a user's browser. While there are no reported vulnerabilities or CVEs, the lack of auth checks on AJAX handlers and the low output escaping rate represent substantial risks that could be exploited. The plugin's strengths lie in its SQL handling and lack of historical vulnerabilities, but these are overshadowed by immediate, exploitable weaknesses in its entry points and output sanitization.
Key Concerns
- AJAX handlers without auth checks
- Low percentage of properly escaped output
CB Contact Form Security Vulnerabilities
CB Contact Form Code Analysis
Output Escaping
CB Contact Form Attack Surface
AJAX Handlers 2
WordPress Hooks 1
Maintenance & Trust
CB Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
CB Contact Form Alternatives
Contact Form 7
contact-form-7
Just another contact form plugin. Simple but flexible.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
CB Contact Form Developer Profile
1 plugin · 60 total installs
How We Detect CB Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cb-contact-form/cb-contact-form.css/wp-content/plugins/cb-contact-form/cb-contact-form.js/wp-content/plugins/cb-contact-form/cb-contact-form.jscb-contact-form.css?ver=1.1cb-contact-form.js?ver=1.1HTML / DOM Fingerprints
/wp-json/cb-contact-form/v1