
Contact Info Security & Risk Analysis
wordpress.org/plugins/contact-infoThis plugin will allow you to add contact information from admin panel and show them in frontend. Using shortcodes and functions.
Is Contact Info Safe to Use in 2026?
Generally Safe
Score 85/100Contact Info has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "contact-info" plugin v3.1.8 demonstrates a generally good security posture based on the provided static analysis. The absence of any known CVEs in its history and the analysis showing no critical or high severity taint flows are positive indicators. Furthermore, the plugin utilizes prepared statements for all its SQL queries, which is a strong defense against SQL injection vulnerabilities. The presence of a nonce check and a limited attack surface with no unprotected entry points are also commendable security practices.
However, there are areas for improvement. A significant concern is the low percentage of properly escaped output (29%). This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed in users' browsers if untrusted data is directly rendered without sufficient sanitization. The lack of capability checks on the single shortcode entry point, while not explicitly a direct vulnerability if the shortcode is deemed benign, could be a weakness if its functionality were to evolve to handle sensitive operations.
In conclusion, while the "contact-info" plugin has avoided historical vulnerabilities and implements some crucial security measures like prepared statements, the substantial output escaping issue represents a notable risk that should be addressed promptly. Strengthening output sanitization would significantly improve the plugin's overall security.
Key Concerns
- Low percentage of properly escaped output
- No capability checks on entry point
Contact Info Security Vulnerabilities
Contact Info Release Timeline
Contact Info Code Analysis
Output Escaping
Data Flow Analysis
Contact Info Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Contact Info Maintenance & Trust
Maintenance Signals
Community Trust
Contact Info Alternatives
Mobile Contact Line
mobile-contact-line
Simple plugin that allow you add mobile contact line to your wordpress site
Fetchify
clicktoaddress-auto-complete
This plugin adds global address auto-complete functionality to the address forms on the front-end in WooCommerce.
Contact Widgets For Elementor all the contact links you need in one place
contact-widgets-for-elementor
Contact Widgets For Elementor , Now you can add all the beast ways to contact you: Whatsapp, SMS, Facebook messenger, Email, Phone and Waze.
Contact Details
contact-details
Display your contact details with a simple shortcode!
Mobile Only Contact Footer
mobile-only-contact-footer
An editable, fixed position div that sticks to the bottom of web page on mobile devices.
Contact Info Developer Profile
9 plugins · 8K total installs
How We Detect Contact Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-info/css/contact_info.css/wp-content/plugins/contact-info/js/ap.cookie.js/wp-content/plugins/contact-info/js/ap-tabs.jscontact-info/css/contact_info.css?ver=contact-info/js/ap.cookie.js?ver=contact-info/js/ap-tabs.js?ver=HTML / DOM Fingerprints
ci-contact-info|||||<(`0_0`)>()(afo)() ()-()+3 moreap_cookieap_tabs[ci]