
Contact Details Security & Risk Analysis
wordpress.org/plugins/contactAdds the ability to easily enter and display contact information.
Is Contact Details Safe to Use in 2026?
Generally Safe
Score 85/100Contact Details has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'contact' plugin version 0.8.1 exhibits a generally strong security posture based on the static analysis. The plugin demonstrates good development practices by avoiding dangerous functions, implementing prepared statements for all SQL queries, and ensuring a high percentage of output is properly escaped. The absence of file operations and external HTTP requests further reduces the attack surface. The presence of a nonce check and a capability check are positive indicators for securing its entry points. Furthermore, the plugin has no recorded vulnerabilities, including critical or high severity CVEs, suggesting a mature and well-maintained codebase.
However, a potential area for improvement lies in the lack of capability checks on its single entry point, the shortcode. While the static analysis indicates this entry point is currently 'unprotected' from an authentication perspective, the absence of explicit capability checks means any user, regardless of their role, could potentially trigger the shortcode's functionality. This could lead to unintended consequences if the shortcode performs actions that should be restricted. Taint analysis revealing zero flows with unsanitized paths is a very positive sign, indicating no obvious vulnerabilities related to data flow were detected. In conclusion, the plugin is robust in its handling of code execution and data sanitation, but the lack of fine-grained access control on its shortcode presents a minor but notable security consideration.
Key Concerns
- Missing capability checks on shortcode
Contact Details Security Vulnerabilities
Contact Details Code Analysis
Output Escaping
Contact Details Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Contact Details Maintenance & Trust
Maintenance Signals
Community Trust
Contact Details Alternatives
Custom Global Variables
custom-global-variables
Easily create custom variables that can be accessed globally in Wordpress and PHP. Retrieval of information is extremely fast, with no database calls.
Lead info with country for Contact Form 7
contact-form-7-lead-info-with-country
Lead info with country for Contact Form 7 helps to track users that fill in forms.
Contact Information Widget
contact-information-widget
Easily add a Contact Information Widget to your widgetable sidebar. With this plugin you can add a contact information.
AffiliateWP – Order Details For Affiliates
affiliatewp-order-details-for-affiliates
Allow affiliates to see order details on referrals they generated
Export Plugin Details
export-plugin-details
Simple way to export your installed plugins list in CSV format.
Contact Details Developer Profile
4 plugins · 3K total installs
How We Detect Contact Details
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<form method="post" action=""><input type="hidden" name="" id="_nonce" value="