
Contact Form DB for Enfold Security & Risk Analysis
wordpress.org/plugins/contact-form-db-for-enfoldSave All Contact from Enfold Module Contact in DB
Is Contact Form DB for Enfold Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form DB for Enfold has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of contact-form-db-for-enfold v2.0.2 reveals a generally positive security posture, with no direct vulnerabilities identified in the attack surface, dangerous functions, file operations, or external HTTP requests. Furthermore, the vulnerability history shows no previously recorded CVEs, indicating a potentially stable and well-maintained codebase.
However, significant concerns arise from the SQL query handling and output escaping. The analysis indicates that 100% of the SQL queries are not using prepared statements, which presents a high risk of SQL injection vulnerabilities. Additionally, none of the identified output points are properly escaped, leaving the plugin susceptible to Cross-Site Scripting (XSS) attacks. The absence of nonce and capability checks across the board, though not directly exploitable due to the lack of entry points in this specific analysis, points to a potential weakness if new AJAX handlers or REST API routes were to be introduced without proper security measures.
In conclusion, while the plugin benefits from a clean vulnerability history and a minimal attack surface in this version, the critical lack of prepared statements for SQL queries and proper output escaping are significant security weaknesses that require immediate attention to mitigate the risk of severe exploitation.
Key Concerns
- SQL queries without prepared statements
- Output not properly escaped
- No nonce checks
- No capability checks
Contact Form DB for Enfold Security Vulnerabilities
Contact Form DB for Enfold Code Analysis
SQL Query Safety
Output Escaping
Contact Form DB for Enfold Attack Surface
WordPress Hooks 3
Maintenance & Trust
Contact Form DB for Enfold Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form DB for Enfold Alternatives
Contact Form DB for Enfold Developer Profile
3 plugins · 1K total installs
How We Detect Contact Form DB for Enfold
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-db-for-enfold/admin/js/ecf_scripts.js/wp-content/plugins/contact-form-db-for-enfold/admin/css/ecf_style.css/wp-content/plugins/contact-form-db-for-enfold/admin/js/ecf_scripts.jscontact-form-db-for-enfold/admin/js/ecf_scripts.js?ver=contact-form-db-for-enfold/admin/css/ecf_style.css?ver=HTML / DOM Fingerprints
<!-- @deactivated_plugin -->