CFW – Contact Form Chat Security & Risk Analysis

wordpress.org/plugins/cfw-contact-form-chat

Create customizable contact forms that send messages directly to WhatsApp. Supports Arabic, multiple forms, and CSV export.

10 active installs v1.0.0 PHP 7.4+ WP 5.0+ Updated Aug 1, 2025
contact-formcsvexportformswhatsapp
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is CFW – Contact Form Chat Safe to Use in 2026?

Generally Safe

Score 100/100

CFW – Contact Form Chat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "cfw-contact-form-chat" plugin version 1.0.0 exhibits a generally strong security posture, primarily due to the absence of known vulnerabilities and the implementation of several good security practices. The static analysis reveals a well-managed attack surface with no unprotected entry points, indicating that all AJAX handlers, REST API routes (if any were present), and shortcodes are likely protected by authentication and capability checks. The plugin also demonstrates a good use of prepared statements for SQL queries and proper output escaping, with 86% and 81% respectively, which are crucial for preventing common web vulnerabilities like SQL injection and Cross-Site Scripting (XSS).

However, despite these strengths, there are minor areas for improvement. The taint analysis did not reveal any critical or high-severity issues, which is a very positive sign. Similarly, the complete lack of any recorded vulnerabilities in its history further reinforces a good track record. The presence of nonce checks and capability checks on some AJAX handlers is a positive step, but the data doesn't explicitly state that ALL AJAX handlers have these checks, leaving a slight ambiguity. The analysis also reports 0 file operations and 0 external HTTP requests, which minimizes risks associated with file manipulation and external service dependencies.

In conclusion, "cfw-contact-form-chat" v1.0.0 appears to be a secure plugin based on the provided data. Its strengths lie in the absence of known vulnerabilities, protected entry points, and good practices in SQL and output handling. The primary weakness, if any, is the minor ambiguity in the comprehensive application of nonce and capability checks across all potential entry points. Overall, the risk is assessed as low.

Key Concerns

  • Potential for missing comprehensive auth checks on AJAX
  • Some SQL queries are not using prepared statements
  • Some outputs are not properly escaped
Vulnerabilities
None known

CFW – Contact Form Chat Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CFW – Contact Form Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
6 prepared
Unescaped Output
14
60 escaped
Nonce Checks
4
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

86% prepared7 total queries

Output Escaping

81% escaped74 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
cfwchat_reports_page (includes\class-reports.php:17)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CFW – Contact Form Chat Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_cfwchat_save_messageincludes\class-ajax.php:6
noprivwp_ajax_cfwchat_save_messageincludes\class-ajax.php:7

Shortcodes 1

[cfw-contact-form-chat] includes\class-fields.php:167
WordPress Hooks 11
actionwp_enqueue_scriptscfw-contact-form-chat.php:64
actionadmin_enqueue_scriptscfw-contact-form-chat.php:89
actionadmin_enqueue_scriptscfw-contact-form-chat.php:147
actioninitincludes\class-cpt.php:27
filtermanage_cfwchat_form_posts_columnsincludes\class-cpt.php:29
filtermanage_cfwchat_form_posts_columnsincludes\class-cpt.php:37
actionmanage_cfwchat_form_posts_custom_columnincludes\class-cpt.php:50
actionadd_meta_boxesincludes\class-fields.php:6
actionsave_post_cfwchat_formincludes\class-fields.php:102
actionadmin_menuincludes\class-reports.php:6
actionadmin_post_cfwchat_exportincludes\class-reports.php:91
Maintenance & Trust

CFW – Contact Form Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 1, 2025
PHP min version7.4
Downloads278

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

CFW – Contact Form Chat Developer Profile

aa96me

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CFW – Contact Form Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about CFW – Contact Form Chat