Contact Form DB Divi Security & Risk Analysis

wordpress.org/plugins/contact-form-db-divi

The Contact Form DB plugin is designed to provide an easy way to store and manage form submissions on your Divi website

3K active installs v1.3.2 PHP 5.6+ WP 5.0+ Updated Oct 5, 2025
contact-form-databasedividivi-contact-form-databasedivi-contact-form-db
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form DB Divi Safe to Use in 2026?

Generally Safe

Score 100/100

Contact Form DB Divi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The static analysis of the contact-form-db-divi plugin v1.3.2 reveals a generally strong security posture. The plugin demonstrates good practices by avoiding dangerous functions, implementing prepared statements for all SQL queries, and properly escaping the vast majority of its output. Crucially, the absence of any reported vulnerabilities in its history, including critical or high severity ones, further reinforces this positive outlook. The plugin also incorporates a nonce check, indicating an awareness of common WordPress security mechanisms.

However, there are a few areas that prevent a perfect score. The plugin lacks capability checks, which is a concern as it means any authenticated user could potentially interact with its functionality without proper authorization checks. While the attack surface appears to be zero for AJAX handlers, REST API routes, shortcodes, and cron events, this is based on the static analysis and could be more robust with explicit capability checks where applicable. The presence of a bundled Freemius library, version 1.0, also raises a potential concern as older versions of bundled libraries can sometimes harbor unpatched vulnerabilities, though no specific issues were identified in this analysis. Overall, the plugin appears secure with good coding practices, but the absence of capability checks and the version of the bundled library present minor areas for improvement.

Key Concerns

  • Missing capability checks
  • Bundled outdated Freemius v1.0 library
Vulnerabilities
None known

Contact Form DB Divi Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form DB Divi Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
29 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

97% escaped30 total outputs
Attack Surface

Contact Form DB Divi Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
filterpricing/show_annual_in_monthlycontact-form-db-divi.php:61
actionadmin_initcontact-form-db-divi.php:83
actioninitincludes\class-lwp-cfdb-form-submission-cpt.php:14
filterpost_row_actionsincludes\class-lwp-cfdb-form-submission-cpt.php:16
filtermanage_lwp_form_submission_posts_columnsincludes\class-lwp-cfdb-form-submission-cpt.php:23
actionmanage_lwp_form_submission_posts_custom_columnincludes\class-lwp-cfdb-form-submission-cpt.php:25
actionadmin_noticesincludes\class-lwp-cfdb-form-submission-cpt.php:32
actionet_pb_contact_form_submitincludes\class-lwp-cfdb-form-submission-creator.php:14
actionadd_meta_boxesincludes\class-lwp-cfdb-form-submission-meta-boxes.php:16
filteret_pb_all_fields_unprocessed_et_pb_contact_formincludes\class-lwp-cfdb-modify-module.php:14
actionadmin_initincludes\class-lwp-cfdb-rating.php:28
actionadmin_initincludes\class-lwp-cfdb-rating.php:29
actionadmin_noticesincludes\class-lwp-cfdb-rating.php:59
Maintenance & Trust

Contact Form DB Divi Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 5, 2025
PHP min version5.6
Downloads32K

Community Trust

Rating78/100
Number of ratings9
Active installs3K
Developer Profile

Contact Form DB Divi Developer Profile

learnhowwp

9 plugins · 31K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form DB Divi

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contact-form-db-divi/assets/css/style.css/wp-content/plugins/contact-form-db-divi/assets/js/custom.js
Script Paths
/wp-content/plugins/contact-form-db-divi/assets/js/custom.js
Version Parameters
contact-form-db-divi/assets/css/style.css?ver=contact-form-db-divi/assets/js/custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
lwp_cfdb_read_status
HTML Comments
<!-- The plugin saves all form submission made to Divi forms in the WordPress backend. --><!-- A constant to store the current version of the plugin. --><!-- A global variable to check if the version of the plugin is the free version. --><!-- Create a helper function for easy SDK access. -->+22 more
Data Attributes
post_type="lwp_form_submission"key="lwp_cfdb_read_status"value="false"
JS Globals
lwp_cfdb_is_free_version$lwp_cfdd_fslwp_cfdd_fs$lwp_cfdb_is_free_versionlwp_cfdb_check_upgrade_callbacklwp_cfdb_activation_hook
FAQ

Frequently Asked Questions about Contact Form DB Divi