
Contact Form Multi by BestWebSoft – Multiple Forms Plugin for Single WordPress Website Security & Risk Analysis
wordpress.org/plugins/contact-form-multiAdd unlimited number of contact forms to WordPress website.
Is Contact Form Multi by BestWebSoft – Multiple Forms Plugin for Single WordPress Website Safe to Use in 2026?
Generally Safe
Score 100/100Contact Form Multi by BestWebSoft – Multiple Forms Plugin for Single WordPress Website has a strong security track record. Known vulnerabilities have been patched promptly.
The "contact-form-multi" plugin v1.3.1 exhibits a generally strong security posture based on the static analysis. The absence of unprotected entry points (AJAX, REST API, shortcodes, cron) is a significant positive. Furthermore, the plugin demonstrates good coding practices with a high percentage of properly escaped output and a robust number of nonce and capability checks. The taint analysis reveals no critical or high-severity issues, and there are no unsanitized path flows, indicating a low risk of direct code injection or path traversal vulnerabilities stemming from user input.
However, a historical medium-severity Cross-Site Scripting (XSS) vulnerability from 2017, though currently patched, warrants consideration. While the static analysis doesn't reveal immediate XSS risks in this version, it highlights a past area of concern. The presence of raw SQL queries (50% not using prepared statements) is a potential, albeit minor, concern. While the total number is low, unescaped or improperly parameterized SQL queries can lead to SQL injection if not handled carefully. The file operations and external HTTP requests, while present, do not show immediate signs of risk in the static analysis but represent potential areas for future vulnerabilities if not managed with strict input validation and output sanitization.
In conclusion, "contact-form-multi" v1.3.1 appears to be a relatively secure plugin, with a strong emphasis on preventing common web vulnerabilities. The development team has implemented good security measures. The main weakness lies in the historical vulnerability and the 50% rate of non-prepared SQL statements, which, while not critical in this analysis, could be improved for enhanced long-term security.
Key Concerns
- SQL queries not using prepared statements (50%)
- Past medium severity XSS vulnerability
Contact Form Multi by BestWebSoft – Multiple Forms Plugin for Single WordPress Website Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Contact Form Multi by BestWebSoft – Multiple Forms Plugin for Single WordPress Website < 1.2.1 - Reflected Cross-Site Scripting
Contact Form Multi by BestWebSoft – Multiple Forms Plugin for Single WordPress Website Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Contact Form Multi by BestWebSoft – Multiple Forms Plugin for Single WordPress Website Attack Surface
AJAX Handlers 3
WordPress Hooks 16
Maintenance & Trust
Contact Form Multi by BestWebSoft – Multiple Forms Plugin for Single WordPress Website Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form Multi by BestWebSoft – Multiple Forms Plugin for Single WordPress Website Alternatives
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress
contact-form-to-db
Save and manage Contact Form messages. Never lose important data.
GB Forms DB
gb-forms-db
One lead collector to rule them all! The best place to save all your leads from all forms in one place! Easily manage, export or post all your leads …
Code Snippets
code-snippets
An easy, clean and simple way to enhance your site with code snippets.
Loco Translate
loco-translate
Translate WordPress plugins and themes directly in your browser. Versatile PO file editor with integrated AI translation providers.
ManageWP Worker
worker
A better way to manage dozens of WordPress websites.
Contact Form Multi by BestWebSoft – Multiple Forms Plugin for Single WordPress Website Developer Profile
32 plugins · 17K total installs
How We Detect Contact Form Multi by BestWebSoft – Multiple Forms Plugin for Single WordPress Website
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-multi/css/style.css/wp-content/plugins/contact-form-multi/js/custom.jsContact Form Multi by BestWebSoft 1.3.1/wp-content/plugins/contact-form-multi/js/custom.jscontact-form-multi/css/style.css?ver=contact-form-multi/js/custom.js?ver=HTML / DOM Fingerprints
bws_formscntctfrmmlt_main_menuCopyright 2021 BestWebSoft ( https://support.bestwebsoft.com )This program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+14 moredata-idcntctfrmmlt_options_main