
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress Security & Risk Analysis
wordpress.org/plugins/contact-form-to-dbSave and manage Contact Form messages. Never lose important data.
Is Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress Safe to Use in 2026?
Generally Safe
Score 92/100Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The "contact-form-to-db" plugin exhibits a mixed security posture. While it demonstrates good practices in many areas, such as a high percentage of prepared SQL statements and properly escaped output, several concerning signals warrant attention. The presence of dangerous functions like `unserialize` and a taint analysis revealing a high-severity flow with unsanitized paths are significant red flags. Furthermore, the plugin has a history of 5 known CVEs, including past critical and high-severity vulnerabilities related to SQL Injection and Cross-site Scripting, indicating a recurring pattern of security weaknesses. The existence of one unprotected AJAX handler further amplifies the attack surface. Although there are no currently unpatched CVEs, the historical data and the specific code signals suggest a need for careful review and potential remediation to mitigate risks.
Key Concerns
- Unprotected AJAX handler
- High severity unsanitized taint flow
- Dangerous function: unserialize
- History of 1 critical CVE
- History of 2 high CVEs
- History of SQL Injection vulnerabilities
- History of Cross-site Scripting vulnerabilities
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress <= 1.7.2 - Authenticated (Author+) SQL Injection
Contact Form to DB by BestWebSoft <= 1.7.1 - Authenticated (Administrator+) SQL Injection via 's'
Contact Form to DB by BestWebSoft <= 1.7.0 - Authenticated (Contributor+) SQL Injection via cntctfrmtdb_department
Contact Form to DB <= 1.7.0 - Multiple Cross-Site Scripting
Contact Form to DB <= 1.5.6 - Multiple Cross-Site Scripting
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress Attack Surface
AJAX Handlers 5
WordPress Hooks 21
Maintenance & Trust
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress Alternatives
Contact Form Multi by BestWebSoft – Multiple Forms Plugin for Single WordPress Website
contact-form-multi
Add unlimited number of contact forms to WordPress website.
Call Now Button – The #1 Click to Call Button for WordPress
call-now-button
The web's #1 click to call button for your website! A simple and powerful plugin that adds a Call Now Button to your website.
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Button Generator – Easily Create Custom Buttons with Icons and Analytics
button-generation
Design and display custom buttons anywhere on your site. Add floating or inline buttons with icons, advanced targeting, and built-in analytics.
Floating Button – Easily Create Sticky, Fixed & Floating Buttons
floating-button
Floating Buttons let you easily create sticky, fixed, and floating action buttons
Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress Developer Profile
32 plugins · 17K total installs
How We Detect Contact Form to DB by BestWebSoft – Messages Database Plugin For WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-to-db/css/bws-admin-style.css/wp-content/plugins/contact-form-to-db/css/bws-plugin-style.css/wp-content/plugins/contact-form-to-db/css/cntctfrmtdb-admin.css/wp-content/plugins/contact-form-to-db/css/cntctfrmtdb-style.css/wp-content/plugins/contact-form-to-db/js/bws-admin-script.js/wp-content/plugins/contact-form-to-db/js/cntctfrmtdb-admin.js/wp-content/plugins/contact-form-to-db/js/cntctfrmtdb-script.js/wp-content/plugins/contact-form-to-db/js/bws-admin-script.js/wp-content/plugins/contact-form-to-db/js/cntctfrmtdb-admin.js/wp-content/plugins/contact-form-to-db/js/cntctfrmtdb-script.jscontact-form-to-db/css/bws-admin-style.css?ver=contact-form-to-db/css/bws-plugin-style.css?ver=contact-form-to-db/css/cntctfrmtdb-admin.css?ver=contact-form-to-db/css/cntctfrmtdb-style.css?ver=contact-form-to-db/js/bws-admin-script.js?ver=contact-form-to-db/js/cntctfrmtdb-admin.js?ver=contact-form-to-db/js/cntctfrmtdb-script.js?ver=HTML / DOM Fingerprints
cntctfrmtdb_manager_pagebws_notice_textbws_plugin_settings_tabsbws_plugin_settings_contentbws_plugin_settings_content_pageCopyright 2021 BestWebSoftThis program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be usefulYou should have received a copy of the GNU General Public License+14 moredata-bws-versiondata-bws-plugincntctfrmtdb_admin_scriptcntctfrmtdb_script