
Contact Bot Security & Risk Analysis
wordpress.org/plugins/contact-botA simple and friendly contact bot
Is Contact Bot Safe to Use in 2026?
Generally Safe
Score 85/100Contact Bot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'contact-bot' v1.5 plugin presents a mixed security posture. On the positive side, it demonstrates good practices in SQL query handling by exclusively using prepared statements and has no recorded vulnerability history, suggesting a generally well-maintained codebase. The presence of capability checks and Lodash, a commonly used library, are also neutral to positive indicators. However, significant concerns arise from the static analysis. A substantial attack surface exists with 9 AJAX handlers, 4 of which lack authentication checks. This is a major security risk, potentially allowing unauthorized users to trigger sensitive actions. Furthermore, the use of the `unserialize` function without proper sanitization of input is a critical vulnerability, as it can lead to Remote Code Execution (RCE) if an attacker can control the serialized data. The low percentage of properly escaped output (29%) also indicates a risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis revealing 2 unsanitized paths, though not classified as critical or high severity in this analysis, points to potential vulnerabilities that could be exploited, especially when combined with other weaknesses.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function: unserialize
- Low output escaping percentage
- Taint analysis shows unsanitized paths
- Missing nonce checks on AJAX
Contact Bot Security Vulnerabilities
Contact Bot Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Contact Bot Attack Surface
AJAX Handlers 9
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Contact Bot Maintenance & Trust
Maintenance Signals
Community Trust
Contact Bot Alternatives
ChatBot Conversational Forms
conversational-forms
ChatBot for WordPress WPBot Addon. Build conversational forms for ChatBot for Lead Generation & more inside the WPBot ChatBot.
AI Chatbot, Assistant Generator, Custom Form Builder for Everest Forms
ai-contact-form
AI Contact Form addon is the perfect addition to your website’s forms. Turn your boring WordPress forms into interactive ones by integrating OpenAI in …
Chat-In Inc
chat-in
Chat-In es una solucion integral al momento de obtener contactos de tu página.
Authyo ChatLead – Chatbot Lead Capture
authyo-chatlead
Capture and verify leads with Authyo OTP APIs. Interactive chatbot with email and phone verification, customizable forms, and lead management.
ChatReact – AI Chatbot, Smart Forms & FAQs
chatreact
Add an AI-powered chatbot, anti-spam contact forms, and FAQ accordions to your WordPress site. No coding required.
Contact Bot Developer Profile
1 plugin · 10 total installs
How We Detect Contact Bot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-bot/style.css/wp-content/plugins/contact-bot/mcb-js/bootstrap.bundle.min.js/wp-content/plugins/contact-bot/mcb-js/jquery.min.js/wp-content/plugins/contact-bot/mcb-js/sweetalert.min.js/wp-content/plugins/contact-bot/mcb-js/contact-bot.jscontact-bot/mcb-js/bootstrap.bundle.min.jscontact-bot/mcb-js/jquery.min.jscontact-bot/mcb-js/sweetalert.min.jscontact-bot/mcb-js/contact-bot.jscontact-bot/style.css?ver=contact-bot/mcb-js/bootstrap.bundle.min.js?ver=contact-bot/mcb-js/jquery.min.js?ver=contact-bot/mcb-js/sweetalert.min.js?ver=contact-bot/mcb-js/contact-bot.js?ver=HTML / DOM Fingerprints
mcb-chat<!-- Contact Bot --><!-- end contact bot -->data-plugin="contact-bot"ContactBot/wp-json/contact-bot/v1/send_message/wp-json/contact-bot/v1/get_updates[contact-bot]