
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress Security & Risk Analysis
wordpress.org/plugins/contact-form-pluginThe most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Is Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress Safe to Use in 2026?
Generally Safe
Score 92/100Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "contact-form-plugin" v4.3.6 presents a mixed security posture. On one hand, the static analysis indicates strong adherence to secure coding practices, with a very high percentage of properly escaped output and a significant number of nonce and capability checks, suggesting developers have implemented robust input validation and access control for many functions. The absence of critical or high-severity taint flows and dangerous functions further bolsters this positive assessment, indicating that at least in the analyzed code, sensitive data handling and execution paths appear to be well-secured against common injection attacks.
However, significant concerns arise from the plugin's vulnerability history. With a total of 10 known CVEs and one currently unpatched high-severity vulnerability, this plugin has a history of exposing users to significant risks. The common vulnerability types like Cross-site Scripting and Missing Authorization, combined with the recent unpatched high-severity issue, highlight a recurring pattern of weaknesses that require immediate attention. While the current static analysis for v4.3.6 shows improvements, the past indicates a potential for underlying architectural flaws or a delay in addressing security fixes, which could still pose a risk if not fully remediated.
In conclusion, while v4.3.6 shows improved code quality with excellent output escaping and a protected attack surface in the static analysis, the plugin's past security record, particularly the unpatched high-severity vulnerability, demands caution. Users should prioritize updating to a version that addresses all known vulnerabilities, especially the one flagged as unpatched. The plugin demonstrates strengths in secure coding for the analyzed version but a historical weakness in timely vulnerability remediation.
Key Concerns
- Currently unpatched high-severity CVE
- 50% of SQL queries not using prepared statements
- 3 flows with unsanitized paths
- 9 medium severity CVEs in history
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
Contact Form by BestWebSoft <= 4.3.6 - Missing Authorization
Contact Form by BestWebSoft <= 4.2.8 - Reflected Cross-Site Scripting via cntctfrm_contact_subject
Contact Form by BestWebSoft <= 4.2.8 - Reflected Cross-Site Scripting via cntctfrm_contact_address
Contact Form by BestWebSoft – Advanced Contact Us Form Builder for WordPress <= 4.0.1 - Cross-Site Scripting
Contact Form by BestWebSoft <= 3.95 - ReflectedCross-Site Scripting
Advanced Contact Us Form Builder for WordPress <= 4.0.5 - Reflected Cross-Site Scripting
Contact Form <= 3.82 - Authorization Bypass
Contact Form Plugin <= 3.81 - Unauthenticated Stored Cross-Site Scripting
Contact Form By BestWebSoft<= 3.34 - Cross-Site Scripting
Contact Form by BestWebSoft <= 3.51 - Cross-Site Scripting
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress Release Timeline
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress Attack Surface
AJAX Handlers 4
Shortcodes 2
WordPress Hooks 22
Maintenance & Trust
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress Alternatives
Visitor Contact Forms
visitorcontact
Create customizable contact forms and sticky contact button for your WordPress blog. Web 2.0 style.
EngageDock AI – Smart Support Assistant
engagedock-ai-smart-support-assistant
Floating contact widget with click-to-call, click-to-text, callback form, business hours, vCard, and analytics.
Floating Contact Widget: Chat & Call
floating-contact-widget-chat-call
A floating chat and call widget for WordPress. Add WhatsApp chat & call buttons to your site for quick customer interaction.
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
Buttonizer – Live Chat, AI Chatbot, Call, Chat, Contact Button
button-contact-vr
Powerful platform with Live Chat, AI Chatbots, and Real-Time Visitor Monitoring! Also, create Call, Email, SMS, & Contact buttons to increase conv …
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress Developer Profile
18 plugins · 207K total installs
How We Detect Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-plugin/css/cntctfrm-style.css/wp-content/plugins/contact-form-plugin/js/cntctfrm-scripts.js/wp-content/plugins/contact-form-plugin/includes/build/index.js/wp-content/plugins/contact-form-plugin/includes/build/index.asset.php/wp-content/plugins/contact-form-plugin/js/cntctfrm-scripts.js/wp-content/plugins/contact-form-plugin/includes/build/index.jscontact-form-plugin/css/cntctfrm-style.css?ver=contact-form-plugin/js/cntctfrm-scripts.js?ver=contact-form-plugin/includes/build/index.js?ver=HTML / DOM Fingerprints
cntctfrm-wrapcntctfrm_form<!-- Start Contact Form by BestWebSoft --><!-- End Contact Form by BestWebSoft -->data-cntctfrm-iddata-cntctfrm-noncecntctfrm_params