
Custom Contact Details With WP List Security & Risk Analysis
wordpress.org/plugins/custom-contact-details-with-wp-listThis plugin create custom Contact Details list from database using WP List. (Crud Operations Using WP List)
Is Custom Contact Details With WP List Safe to Use in 2026?
Generally Safe
Score 85/100Custom Contact Details With WP List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "custom-contact-details-with-wp-list" v1.0.0 plugin exhibits a mixed security posture. On the positive side, there are no known CVEs, a good sign regarding its historical security. The plugin also demonstrates awareness of security by including a nonce check, and no external HTTP requests or file operations are present, which reduces potential attack vectors.
However, significant concerns arise from the static analysis. The taint analysis reveals two high-severity flows with unsanitized data, indicating a potential for vulnerabilities if these flows are reachable by attackers. Furthermore, the output escaping is worryingly low at 38%, suggesting a high likelihood of cross-site scripting (XSS) vulnerabilities. While the plugin avoids dangerous functions and uses prepared statements for the majority of its SQL queries, the lack of capability checks and the presence of unsanitized paths in the taint analysis are critical weaknesses that could be exploited.
In conclusion, while the plugin has a clean vulnerability history, the current code analysis flags serious potential risks. The low output escaping percentage and the high-severity taint flows are the most immediate threats. The absence of capability checks on any potential entry points (though none were found to be unprotected) is also a concern for future development or if the plugin's functionality evolves. Users should exercise caution until these issues are addressed.
Key Concerns
- High severity taint flows
- Low output escaping percentage
- Unsanitized paths found in taint analysis
- No capability checks
Custom Contact Details With WP List Security Vulnerabilities
Custom Contact Details With WP List Release Timeline
Custom Contact Details With WP List Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Custom Contact Details With WP List Attack Surface
WordPress Hooks 2
Maintenance & Trust
Custom Contact Details With WP List Maintenance & Trust
Maintenance Signals
Community Trust
Custom Contact Details With WP List Alternatives
Simple Table Manager
simple-table-manager
Enables viewing and editing table records and exporting them to CSV files through a minimal database interface from your dashboard.
Crudiator
crudiator
Crudiator is a plugin that makes it easy to achieve CRUD operations on custom tables in the WordPress admin panel.
WP-DBManager
wp-dbmanager
Manages your WordPress database.
Plugins Garbage Collector (Database Cleanup)
plugins-garbage-collector
Find unused database tables from deactivated or deleted plugins. You can delete unused database tables to reduce database volume and enhance site perf …
Change Table Prefix
change-table-prefix
Change the database table prefix first defined in your wp-config.php file.
Custom Contact Details With WP List Developer Profile
12 plugins · 1K total installs
How We Detect Custom Contact Details With WP List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-contact-details-with-wp-list/admin/css/style.css/wp-content/plugins/custom-contact-details-with-wp-list/admin/js/custom-js.js/wp-content/plugins/custom-contact-details-with-wp-list/admin/js/custom-js.jscustom-contact-details-with-wp-list/admin/css/style.css?ver=custom-contact-details-with-wp-list/admin/js/custom-js.js?ver=HTML / DOM Fingerprints
wp-list-tablewidefatfixedstripeddata-id