
Contact Forms by Cimatti Security & Risk Analysis
wordpress.org/plugins/contact-formsCreate and publish forms in your WordPress website with drag and drop. Contact forms, landing page forms, invitations, and more.
Is Contact Forms by Cimatti Safe to Use in 2026?
Generally Safe
Score 91/100Contact Forms by Cimatti has a strong security track record. Known vulnerabilities have been patched promptly.
The "contact-forms" plugin v1.9.13 presents a mixed security posture. While it demonstrates some good practices like a significant percentage of SQL queries using prepared statements and a good number of nonce and capability checks, several concerning areas exist. The static analysis highlights a notable attack surface with 12 entry points, of which 2 lack authentication checks, making them prime targets for unauthorized actions. The presence of dangerous functions like `unserialize` and `create_function`, coupled with a very low percentage (6%) of properly escaped output, strongly indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals 6 high-severity flows with unsanitized paths, suggesting potential for data manipulation or execution vulnerabilities.
The plugin's vulnerability history is particularly worrying, with 11 known CVEs, all of which are currently patched. However, the prevalence of medium and high severity vulnerabilities, specifically CSRF, Missing Authorization, and XSS, in the past indicates a recurring pattern of weaknesses in its security implementation. The last reported vulnerability was recent (2025-06-02), which, despite being patched, underscores the ongoing need for vigilance. The combination of direct code vulnerabilities and historical patterns suggests that this plugin, while not currently exposing unpatched critical issues, carries inherent risks due to its codebase and past security record.
Key Concerns
- Unprotected AJAX handlers
- High-severity unsanitized taint flows
- Dangerous functions present (`unserialize`, `create_function`)
- Very low output escaping percentage
- Previous high severity vulnerabilities
- Previous medium severity vulnerabilities
Contact Forms by Cimatti Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
Contact Forms by Cimatti Plugin <= 1.9.8 - Cross-Site Request Forgery
WordPress Contact Forms by Cimatti <= 1.9.4 - Missing Authorization to Unauthenticated Form Submission Download
WordPress Contact Forms by Cimatti <= 1.9.2 - Cross-Site Request Forgery via process_bulk_action Function
Contact Forms by Cimatti <= 1.8.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Contact Forms by Cimatti <= 1.7.0 - Unauthenticated Stored Cross-Site Scripting
Contact Forms by Cimatti <= 1.6.0 - Cross-Site Request Forgery via accua_forms_list_page_table
WordPress Contact Forms by Cimatti <= 1.5.7 - Missing Authorization
WordPress Contact Forms by Cimatti <= 1.5.7 - Cross-Site Request Forgery via _accua_forms_form_edit_action
WordPress Contact Forms by Cimatti <= 1.5.4 - Unauthenticated Stored Cross-Site Scripting
Contact Forms by Cimatti <= 1.5.4 - Reflected Cross-Site Scripting via 'form-field-id', 'edit-fid', 'id', 'name', 'type', 'description' Parameters
Cimatti Contact Forms <= 1.4.11 - Cross-Site Scripting
Contact Forms by Cimatti Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Contact Forms by Cimatti Attack Surface
AJAX Handlers 11
Shortcodes 1
WordPress Hooks 18
Maintenance & Trust
Contact Forms by Cimatti Maintenance & Trust
Maintenance Signals
Community Trust
Contact Forms by Cimatti Alternatives
WS Form LITE – Drag & Drop Contact Form Builder
ws-form
Contact form builder for WordPress. Create professional, accessible, mobile-friendly forms in minutes without coding.
Lead Generation Form
lead-generation-form
Create lead forms with drag-and-drop builder, capture leads, and export data easily.
Connect2Form – Advanced Contact Form Builder
connect2form-advanced-contact-form-builder-with-marketing-tools
Professional drag-and-drop form builder with accessibility, security, and performance optimization. Extensible with addon integrations.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
Contact Forms by Cimatti Developer Profile
1 plugin · 700 total installs
How We Detect Contact Forms by Cimatti
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-forms/accua.css/wp-content/plugins/contact-forms/chartjs/Chart.min.js/wp-content/plugins/contact-forms/chartjs/Chart.min.jsplugins/contact-forms/accua.css?ver=plugins/contact-forms/chartjs/Chart.min.js?ver=HTML / DOM Fingerprints
accua-forms-versionbtdata-type="contact-forms-field"accua_forms[contact-form-input][contact-form-submit]