
Contact Form in Product Tab WooCommerce by Themeqx.com Security & Risk Analysis
wordpress.org/plugins/contact-from-product-tab-woocommerceIncrease your sales by Contact Form Product Tab WooCommerce. Your buyer can send contact message directly from your product page.
Is Contact Form in Product Tab WooCommerce by Themeqx.com Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form in Product Tab WooCommerce by Themeqx.com has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
This plugin exhibits a concerning security posture primarily due to a significant attack surface exposed through AJAX handlers that lack any authentication or authorization checks. While the plugin does not utilize dangerous functions, perform file operations, or make external HTTP requests, the absence of these fundamental security measures for its AJAX endpoints presents a substantial risk. Any user, regardless of their logged-in status or role, can potentially trigger these AJAX actions, leading to unintended consequences or exploitation if the handlers perform sensitive operations.
The static analysis further highlights issues with output escaping, with a substantial portion of outputs not being properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output without sufficient sanitization. The lack of any recorded vulnerabilities in its history might suggest a lack of targeted attacks or that past issues were promptly addressed, but it does not negate the inherent risks identified in the current code analysis.
In conclusion, while the plugin avoids some common pitfalls like raw SQL queries and bundled libraries, the unprotected AJAX handlers and the significant proportion of unescaped output are critical weaknesses. These findings demand immediate attention to mitigate the risk of unauthorized actions and potential XSS attacks. The plugin's strengths lie in its avoidance of direct SQL manipulation and external calls, but these are overshadowed by the exposed entry points and output sanitization deficiencies.
Key Concerns
- AJAX handlers without auth checks
- Significant portion of outputs not properly escaped
Contact Form in Product Tab WooCommerce by Themeqx.com Security Vulnerabilities
Contact Form in Product Tab WooCommerce by Themeqx.com Release Timeline
Contact Form in Product Tab WooCommerce by Themeqx.com Code Analysis
Output Escaping
Contact Form in Product Tab WooCommerce by Themeqx.com Attack Surface
AJAX Handlers 4
WordPress Hooks 7
Maintenance & Trust
Contact Form in Product Tab WooCommerce by Themeqx.com Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form in Product Tab WooCommerce by Themeqx.com Alternatives
TextMe SMS
textme-sms-integration
Send custom SMS messages from your WordPress site to your customers using the TextMe SMS gateway.
Postcodes4U Address Finder
postcodes4u-address-finder
Requires WooCommerce at least: 2.2.3 Tested WooCommerce up to: 10.5.1 Tested ContactForm7 4.9.2 - 6.1.5 Tested Gravity Forms 2.4.15 - 2.9.
Invisible reCaptcha for WordPress
invisible-recaptcha
Invisible reCaptcha for WordPress plugin helps you to protect your sites against bad spam bots using the new Invisible reCaptcha by Google.
ACF Field For CF7
acf-field-for-contact-form-7
Add a Contact Form 7 field to Advanced Custom Fields. Pick a form, display it. No shortcodes, no hassle.
AFI – The Easiest Integration Plugin
advanced-form-integration
Connect any WordPress form or event to 200+ apps — no code. Send leads, orders, and signups to your CRM, email, or sheets in minutes.
Contact Form in Product Tab WooCommerce by Themeqx.com Developer Profile
5 plugins · 130 total installs
How We Detect Contact Form in Product Tab WooCommerce by Themeqx.com
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-from-product-tab-woocommerce/assets/css/cfptwc-admin.css/wp-content/plugins/contact-from-product-tab-woocommerce/assets/js/cfptwc-admin.js/wp-content/plugins/contact-from-product-tab-woocommerce/assets/js/cfptwc.js/wp-content/plugins/contact-from-product-tab-woocommerce/assets/js/cfptwc-admin.js/wp-content/plugins/contact-from-product-tab-woocommerce/assets/js/cfptwc.js/wp-content/plugins/contact-from-product-tab-woocommerce/assets/css/cfptwc-admin.css?ver=/wp-content/plugins/contact-from-product-tab-woocommerce/assets/js/cfptwc-admin.js?ver=/wp-content/plugins/contact-from-product-tab-woocommerce/assets/js/cfptwc.js?ver=HTML / DOM Fingerprints
cfptwc