
Contact Bot Security & Risk Analysis
wordpress.org/plugins/contact-botA simple and friendly contact bot
Is Contact Bot Safe to Use in 2026?
Generally Safe
Score 85/100Contact Bot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'contact-bot' v1.5 plugin presents a mixed security posture. On the positive side, it demonstrates good practices in SQL query handling by exclusively using prepared statements and has no recorded vulnerability history, suggesting a generally well-maintained codebase. The presence of capability checks and Lodash, a commonly used library, are also neutral to positive indicators. However, significant concerns arise from the static analysis. A substantial attack surface exists with 9 AJAX handlers, 4 of which lack authentication checks. This is a major security risk, potentially allowing unauthorized users to trigger sensitive actions. Furthermore, the use of the `unserialize` function without proper sanitization of input is a critical vulnerability, as it can lead to Remote Code Execution (RCE) if an attacker can control the serialized data. The low percentage of properly escaped output (29%) also indicates a risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis revealing 2 unsanitized paths, though not classified as critical or high severity in this analysis, points to potential vulnerabilities that could be exploited, especially when combined with other weaknesses.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function: unserialize
- Low output escaping percentage
- Taint analysis shows unsanitized paths
- Missing nonce checks on AJAX
Contact Bot Security Vulnerabilities
Contact Bot Release Timeline
Contact Bot Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Contact Bot Attack Surface
AJAX Handlers 9
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Contact Bot Maintenance & Trust
Maintenance Signals
Community Trust
Contact Bot Alternatives
ChatBot Conversational Forms
conversational-forms
ChatBot for WordPress WPBot Addon. Build conversational forms for ChatBot for Lead Generation & more inside the WPBot ChatBot.
AI Chatbot, Assistant Generator, Custom Form Builder for Everest Forms
ai-contact-form
AI Contact Form addon is the perfect addition to your website’s forms. Turn your boring WordPress forms into interactive ones by integrating OpenAI in …
Chat-In Inc
chat-in
Chat-In es una solucion integral al momento de obtener contactos de tu página.
Authyo ChatLead – Chatbot Lead Capture
authyo-chatlead
Capture and verify leads with Authyo OTP APIs. Interactive chatbot with email and phone verification, customizable forms, and lead management.
ChatReact – AI Chatbot, Smart Forms & FAQs
chatreact
Add an AI-powered chatbot, anti-spam contact forms, and FAQ accordions to your WordPress site. No coding required.
Contact Bot Developer Profile
2 plugins · 20 total installs
How We Detect Contact Bot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-bot/style.css/wp-content/plugins/contact-bot/mcb-js/bootstrap.bundle.min.js/wp-content/plugins/contact-bot/mcb-js/jquery.min.js/wp-content/plugins/contact-bot/mcb-js/sweetalert.min.js/wp-content/plugins/contact-bot/mcb-js/contact-bot.jscontact-bot/mcb-js/bootstrap.bundle.min.jscontact-bot/mcb-js/jquery.min.jscontact-bot/mcb-js/sweetalert.min.jscontact-bot/mcb-js/contact-bot.jscontact-bot/style.css?ver=contact-bot/mcb-js/bootstrap.bundle.min.js?ver=contact-bot/mcb-js/jquery.min.js?ver=contact-bot/mcb-js/sweetalert.min.js?ver=contact-bot/mcb-js/contact-bot.js?ver=HTML / DOM Fingerprints
mcb-chat<!-- Contact Bot --><!-- end contact bot -->data-plugin="contact-bot"ContactBot/wp-json/contact-bot/v1/send_message/wp-json/contact-bot/v1/get_updates[contact-bot]