Contact Form in Product Tab WooCommerce by Themeqx.com Security & Risk Analysis

wordpress.org/plugins/contact-from-product-tab-woocommerce

Increase your sales by Contact Form Product Tab WooCommerce. Your buyer can send contact message directly from your product page.

10 active installs v2.0.1 PHP + WP 3.0.1+ Updated Jul 5, 2018
contactcontactform7formmessagewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form in Product Tab WooCommerce by Themeqx.com Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form in Product Tab WooCommerce by Themeqx.com has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

This plugin exhibits a concerning security posture primarily due to a significant attack surface exposed through AJAX handlers that lack any authentication or authorization checks. While the plugin does not utilize dangerous functions, perform file operations, or make external HTTP requests, the absence of these fundamental security measures for its AJAX endpoints presents a substantial risk. Any user, regardless of their logged-in status or role, can potentially trigger these AJAX actions, leading to unintended consequences or exploitation if the handlers perform sensitive operations.

The static analysis further highlights issues with output escaping, with a substantial portion of outputs not being properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output without sufficient sanitization. The lack of any recorded vulnerabilities in its history might suggest a lack of targeted attacks or that past issues were promptly addressed, but it does not negate the inherent risks identified in the current code analysis.

In conclusion, while the plugin avoids some common pitfalls like raw SQL queries and bundled libraries, the unprotected AJAX handlers and the significant proportion of unescaped output are critical weaknesses. These findings demand immediate attention to mitigate the risk of unauthorized actions and potential XSS attacks. The plugin's strengths lie in its avoidance of direct SQL manipulation and external calls, but these are overshadowed by the exposed entry points and output sanitization deficiencies.

Key Concerns

  • AJAX handlers without auth checks
  • Significant portion of outputs not properly escaped
Vulnerabilities
None known

Contact Form in Product Tab WooCommerce by Themeqx.com Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Contact Form in Product Tab WooCommerce by Themeqx.com Release Timeline

v2.0.0
v1.0
Code Analysis
Analyzed Mar 17, 2026

Contact Form in Product Tab WooCommerce by Themeqx.com Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
49
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

17% escaped59 total outputs
Attack Surface
4 unprotected

Contact Form in Product Tab WooCommerce by Themeqx.com Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_cfptwc_save_form_dataclasses\themeqx_cfptwc_ajax.php:30
noprivwp_ajax_cfptwc_save_form_dataclasses\themeqx_cfptwc_ajax.php:31
authwp_ajax_cfptwc_edit_custom_fieldclasses\themeqx_cfptwc_ajax.php:33
authwp_ajax_cfptwc_delete_custom_fieldclasses\themeqx_cfptwc_ajax.php:34
WordPress Hooks 7
actionadmin_menuclasses\themeqx_cfptwc_admin_menu.php:30
actionadd_meta_boxesclasses\themeqx_cfptwc_admin_menu.php:32
actionadmin_enqueue_scriptsclasses\themeqx_cfptwc_base.php:34
actionwp_enqueue_scriptsclasses\themeqx_cfptwc_base.php:35
filterwoocommerce_product_tabsclasses\themeqx_cfptwc_base.php:36
actioninitclasses\themeqx_cfptwc_functions.php:9
actionadmin_noticesclasses\themeqx_cfptwc_functions.php:83
Maintenance & Trust

Contact Form in Product Tab WooCommerce by Themeqx.com Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 5, 2018
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Contact Form in Product Tab WooCommerce by Themeqx.com Developer Profile

themeqx

5 plugins · 130 total installs

81
trust score
Avg Security Score
81/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form in Product Tab WooCommerce by Themeqx.com

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contact-from-product-tab-woocommerce/assets/css/cfptwc-admin.css/wp-content/plugins/contact-from-product-tab-woocommerce/assets/js/cfptwc-admin.js/wp-content/plugins/contact-from-product-tab-woocommerce/assets/js/cfptwc.js
Script Paths
/wp-content/plugins/contact-from-product-tab-woocommerce/assets/js/cfptwc-admin.js/wp-content/plugins/contact-from-product-tab-woocommerce/assets/js/cfptwc.js
Version Parameters
/wp-content/plugins/contact-from-product-tab-woocommerce/assets/css/cfptwc-admin.css?ver=/wp-content/plugins/contact-from-product-tab-woocommerce/assets/js/cfptwc-admin.js?ver=/wp-content/plugins/contact-from-product-tab-woocommerce/assets/js/cfptwc.js?ver=

HTML / DOM Fingerprints

JS Globals
cfptwc
FAQ

Frequently Asked Questions about Contact Form in Product Tab WooCommerce by Themeqx.com