
Contact Us Page Security & Risk Analysis
wordpress.org/plugins/contact-us-pageCreate your contact page in seconds with a contact form, map, social icons and your contact info.
Is Contact Us Page Safe to Use in 2026?
Generally Safe
Score 85/100Contact Us Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "contact-us-page" plugin version 1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, performing no file operations, and making no external HTTP requests. All identified SQL queries are properly prepared, and there are no known vulnerabilities (CVEs) associated with this plugin. The attack surface is minimal, with only one entry point (a shortcode) and no unprotected handlers or routes.
However, there are significant concerns. The plugin fails to implement any nonce checks or capability checks, which is a critical oversight for a WordPress plugin, especially considering it has an entry point. The taint analysis reveals two flows with unsanitized paths, indicating potential for command injection or other code execution vulnerabilities, although these are not classified as critical or high severity. Furthermore, a concerningly low percentage (27%) of output is properly escaped, leaving the plugin vulnerable to Cross-Site Scripting (XSS) attacks.
While the plugin has no known vulnerability history, this could be due to its limited usage, recent release, or simply lack of prior thorough auditing. The absence of critical or high-severity issues in the static analysis is a strength, but the identified weaknesses in output escaping and lack of authentication checks represent real and exploitable risks that should be addressed.
Key Concerns
- Unescaped output detected
- Taint flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
Contact Us Page Security Vulnerabilities
Contact Us Page Code Analysis
Output Escaping
Data Flow Analysis
Contact Us Page Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Contact Us Page Maintenance & Trust
Maintenance Signals
Community Trust
Contact Us Page Alternatives
Contact Form 7 extension for Google Map fields
cf7-google-map
This plugin enables the insertion of google maps into contact form 7 as an input field.
Map Field for Contact Form 7
map-field-for-contact-form-7
Add a Google Maps autocomplete address field with a live interactive map to any Contact Form 7 form. Supports draggable marker, address components, an …
Productive Forms – Contact Us, Newsletter Opt-ins & Content Publishing
productive-forms
Prebuilt 'Contact Us' pages, newsletter opt-ins, content sliders, FAQs, team members, and testimonials using Elementor and Gutenberg.
cf7geogle
cf7geogle
This plug-in provides Google Map for Contact Form 7.
Maps for Contact Form 7
map-contact-form-7
Addon of the contact form 7 that adds place field. The places submitted are overlooked by shortcode( 'maps-for-contact-form-7' ).
Contact Us Page Developer Profile
6 plugins · 630 total installs
How We Detect Contact Us Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-us-page/css/cupStyle.csscontact-us-page/css/cupStyle.css?ver=HTML / DOM Fingerprints
contact_us_page