
Contractor Contact Form Website to Workflow Tool Security & Risk Analysis
wordpress.org/plugins/contractor-contact-form-website-to-workflow-toolThis useful plugin is a website to workflow tool that allows contractors to drive leads directly from their own website form inquiries directly into t …
Is Contractor Contact Form Website to Workflow Tool Safe to Use in 2026?
Generally Safe
Score 92/100Contractor Contact Form Website to Workflow Tool has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "contractor-contact-form-website-to-workflow-tool" version 4.5.0 exhibits a generally good security posture with a strong emphasis on secure coding practices. The high percentage of prepared statements for SQL queries and the exceptional rate of output escaping (95%) are commendable. The limited attack surface, with no unprotected entry points, further bolsters its security.
However, there are areas for concern. The taint analysis reveals a high number of flows with unsanitized paths, specifically one classified as high severity. While the plugin has a history of a single medium-severity Cross-Site Scripting vulnerability, this new taint flow warrants careful investigation. The absence of capability checks on any entry points, while not directly exploitable due to the lack of unprotected entry points, represents a missed opportunity for robust access control.
Overall, the plugin is well-developed with good security hygiene. The primary risks stem from the identified unsanitized taint flows. The historical vulnerability, though patched and of medium severity, suggests that input sanitization should remain a focus. The lack of capability checks, while not an immediate critical flaw, is a weakness that could be exploited if the attack surface were to expand or authentication mechanisms were to fail.
Key Concerns
- High severity unsanitized taint flow
- Flows with unsanitized paths detected
- No capability checks on entry points
- History of medium severity XSS vulnerability
Contractor Contact Form Website to Workflow Tool Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Contractor Contact Form Website to Workflow Tool <= 4.0.0 - Reflected Cross-Site Scripting
Contractor Contact Form Website to Workflow Tool Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Contractor Contact Form Website to Workflow Tool Attack Surface
Shortcodes 1
WordPress Hooks 9
Scheduled Events 2
Maintenance & Trust
Contractor Contact Form Website to Workflow Tool Maintenance & Trust
Maintenance Signals
Community Trust
Contractor Contact Form Website to Workflow Tool Alternatives
Contractor Contact Form Website to Workflow Tool Developer Profile
1 plugin · 60 total installs
How We Detect Contractor Contact Form Website to Workflow Tool
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contractor-contact-form-website-to-workflow-tool/asset/css/style.css/wp-content/plugins/contractor-contact-form-website-to-workflow-tool/asset/js/scripts.js/wp-content/plugins/contractor-contact-form-website-to-workflow-tool/asset/js/jquery.validate.min.js/wp-content/plugins/contractor-contact-form-website-to-workflow-tool/asset/js/jquery.form.js/wp-content/plugins/contractor-contact-form-website-to-workflow-tool/asset/js/scripts.js/wp-content/plugins/contractor-contact-form-website-to-workflow-tool/asset/js/jquery.validate.min.js/wp-content/plugins/contractor-contact-form-website-to-workflow-tool/asset/js/jquery.form.jscontractor-contact-form-website-to-workflow-tool/asset/css/style.css?ver=contractor-contact-form-website-to-workflow-tool/asset/js/scripts.js?ver=contractor-contact-form-website-to-workflow-tool/asset/js/jquery.validate.min.js?ver=contractor-contact-form-website-to-workflow-tool/asset/js/jquery.form.js?ver=HTML / DOM Fingerprints
jp-contact-formjp-form-groupjp-form-controljp-btnjp-btn-primary<!-- This is a contact form plugin --><!-- You can customize the form fields in the plugin settings -->data-plugin-name="contractor-contact-form"data-plugin-version="4.5.0"window.jpFormSettingsvar jp_submit_url/wp-json/jp-contact-form/v1/submit<form class="jp-contact-form" method="post"><div class="jp-form-group"><label for="jp-field-name">Name:</label><input type="text" id="jp-field-name" name="name" required>