
Contact Form Query Security & Risk Analysis
wordpress.org/plugins/contact-form-queryAdd a contact form and receive new message notifications directly to your WordPress admin and to your email. Search and filter messages.
Is Contact Form Query Safe to Use in 2026?
Generally Safe
Score 100/100Contact Form Query has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "contact-form-query" plugin v1.9.0 exhibits a mixed security posture. On the positive side, it demonstrates strong practices regarding output escaping (99% proper) and judicious use of prepared statements for SQL queries (65%). The absence of known CVEs and a clean vulnerability history suggest a generally well-maintained codebase over time. However, a significant concern arises from the attack surface analysis, which reveals 11 AJAX handlers completely unprotected by authentication checks. This presents a substantial risk, as any unauthenticated user could potentially trigger these handlers. Furthermore, the taint analysis identified one flow with an unsanitized path of high severity, indicating a potential vulnerability where user-supplied data might be processed in an insecure manner. While the presence of nonce checks (12) and capability checks (13) is encouraging, their effectiveness is undermined by the lack of authorization on a majority of AJAX endpoints.
Key Concerns
- 11 unprotected AJAX handlers
- High severity unsanitized path in taint analysis
Contact Form Query Security Vulnerabilities
Contact Form Query Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Contact Form Query Attack Surface
AJAX Handlers 11
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Contact Form Query Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form Query Alternatives
Form Builder CP
cp-easy-form-builder
Form Builder CP is a contact form plugin for creating contact forms with a visual form builder and email them.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
HTML Forms – Simple WordPress Forms Plugin
html-forms
A simpler, faster, and smarter WordPress forms plugin.
Contact Form Query Developer Profile
20 plugins · 20K total installs
How We Detect Contact Form Query
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-query/assets/css/stcfq-admin.css/wp-content/plugins/contact-form-query/assets/js/stcfq-admin.js/wp-content/plugins/contact-form-query/assets/js/stcfq-admin.jscontact-form-query/assets/css/stcfq-admin.css?ver=contact-form-query/assets/js/stcfq-admin.js?ver=HTML / DOM Fingerprints
stcfq-admindata-noncestcfqadminurl