
Contact Us for WP Security & Risk Analysis
wordpress.org/plugins/contact-us-for-wpA button to reach us anywhere. Contact us form with floating icon on all pages.
Is Contact Us for WP Safe to Use in 2026?
Generally Safe
Score 85/100Contact Us for WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "contact-us-for-wp" plugin version 2.3.3 appears to be relatively strong based on the static analysis. The plugin has a small attack surface with only two AJAX entry points, and critically, neither of these are exposed without authentication. Furthermore, the absence of dangerous functions, external HTTP requests, and file operations, along with the use of prepared statements for all SQL queries, are positive indicators. The plugin also demonstrates a commitment to security by including nonce checks.
However, a significant concern arises from the low percentage (16%) of properly escaped output. This suggests a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, as untrusted data processed and displayed by the plugin could be rendered in the user's browser without proper sanitization. The taint analysis revealing zero flows is a positive sign, but it's often less comprehensive than manual code review or dedicated security scanners, especially for complex XSS vectors. The lack of recorded vulnerabilities in its history is encouraging, suggesting a stable and potentially well-maintained codebase, but this should not overshadow the identified output escaping issue.
In conclusion, while the plugin exhibits good practices in areas like authentication for entry points and SQL sanitization, the severe deficiency in output escaping presents a notable risk. The plugin is strong against typical SQL injection and unauthorized access through its entry points, but vulnerable to XSS attacks. Addressing the output escaping issue should be a priority to improve its overall security.
Key Concerns
- Low output escaping percentage
- No capability checks on AJAX
Contact Us for WP Security Vulnerabilities
Contact Us for WP Code Analysis
Output Escaping
Contact Us for WP Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
Contact Us for WP Maintenance & Trust
Maintenance Signals
Community Trust
Contact Us for WP Alternatives
Form – Contact Form
form-forms
Form is advanced solution for WordPress users. Contact Form Is awesome WordPress plugin with many useful features and effects.
Free Contact Us Form plugin ( build in accordance to the GDPR )
free-contact-us
This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Sof …
OweBest Contact Form
ob-contact-form
OweBest Contact form is a simple contact form which works out of the box. Use shortcode on posts or pages to generate OweBest Contact Form.
Smartarget Contact Form
smartarget-contact-form
Allow users to contact you by filling a form
Smartarget Email – Contact Us
smartarget-email-contact-us
Allow customers to contact you using Email
Contact Us for WP Developer Profile
2 plugins · 70 total installs
How We Detect Contact Us for WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-us-for-wp/admin/css/contactuswp-admin.css/wp-content/plugins/contact-us-for-wp/admin/js/contactuswp-admin.js/wp-content/plugins/contact-us-for-wp/public/css/contactuswp-public.css/wp-content/plugins/contact-us-for-wp/public/js/contactuswp-public.js/wp-content/plugins/contact-us-for-wp/admin/js/contactuswp-admin.js/wp-content/plugins/contact-us-for-wp/public/js/contactuswp-public.jscontactuswp-admin.css?ver=contactuswp-admin.js?ver=contactuswp-public.css?ver=contactuswp-public.js?ver=HTML / DOM Fingerprints
contactuswp_sectioncontactuswp-container<!-- Contact Us for WP Form --><!-- Contact Us for WP Floating Button -->data-contactuswp-iddata-contactuswp-settingscontactuswp_params[contactuswp_form][contactuswp_button]