CometLeads Contact Security & Risk Analysis

wordpress.org/plugins/cometleads-contact

Replace your static contact form with a conversational chatbot and you’ll see more leads coming your way.

0 active installs v1.0.0 PHP 5.3+ WP 4.8+ Updated Aug 16, 2018
chatbotcometleadscustomerlead-generationleads
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CometLeads Contact Safe to Use in 2026?

Generally Safe

Score 85/100

CometLeads Contact has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "cometleads-contact" plugin version 1.0.0 exhibits a strong adherence to several secure coding practices. Notably, the absence of any identified dangerous functions, SQL queries that are 100% prepared, and no recorded file operations or external HTTP requests are positive indicators. The lack of known CVEs and a clean vulnerability history further suggest a plugin that has historically been secure. However, there are significant areas of concern that warrant attention. The complete absence of nonce checks and capability checks, coupled with a concerningly low percentage of properly escaped outputs, presents a considerable risk. These oversights can leave the plugin vulnerable to various attacks, including Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS), especially if any new entry points or functionalities are introduced in future versions without proper security considerations.

While the current static analysis shows a zero attack surface and no critical taint flows, this may be a reflection of the limited scope of the analysis or the plugin's current functionality. The lack of proper output escaping is a critical weakness that could be exploited even with a seemingly small attack surface. The plugin's current security posture is a mix of good practices in some areas and significant oversights in others. The historical lack of vulnerabilities is a positive sign, but it does not negate the immediate risks posed by the identified coding deficiencies. Future development must prioritize implementing robust authentication and authorization mechanisms, as well as comprehensive output sanitization, to mitigate these inherent risks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Low percentage of properly escaped output
Vulnerabilities
None known

CometLeads Contact Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CometLeads Contact Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

CometLeads Contact Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped3 total outputs
Attack Surface

CometLeads Contact Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedincludes\cmtlc-gull-wordpress-plugin.php:132
actionadmin_enqueue_scriptsincludes\cmtlc-gull-wordpress-plugin.php:147
actionadmin_menuincludes\cmtlc-gull-wordpress-plugin.php:148
actionadmin_initincludes\cmtlc-gull-wordpress-plugin.php:149
actionwp_headincludes\cmtlc-gull-wordpress-plugin.php:151
Maintenance & Trust

CometLeads Contact Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 16, 2018
PHP min version5.3
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CometLeads Contact Developer Profile

jasonleakey

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CometLeads Contact

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cometleads-contact/admin/assets/options.css/wp-content/plugins/cometleads-contact/admin/assets/options.js
Script Paths
https://code.jquery.com/jquery-3.3.1.slim.min.jshttps://cdnjs.cloudflare.com/ajax/libs/popper.js/1.14.3/umd/popper.min.jshttps://stackpath.bootstrapcdn.com/bootstrap/4.1.2/js/bootstrap.min.jshttps://cdnjs.cloudflare.com/ajax/libs/parsley.js/2.8.1/parsley.min.js

HTML / DOM Fingerprints

CSS Classes
switchsliderround
Data Attributes
data-parsley-triggerdata-parsley-required-messagedata-parsley-patterndata-parsley-pattern-message
JS Globals
CMTLC_GULL_PLUGIN_SLUGCMTLC_GULL_BRAND_NAMECMTLC_GULL_TEXT_DOMAINCMTLC_GULL_OPTION_GROUP_NAMECMTLC_GULL_OPTION_NAMECMTLC_GULL_SERVER_HOST
FAQ

Frequently Asked Questions about CometLeads Contact