
FEP Contact Form Security & Risk Analysis
wordpress.org/plugins/fep-contact-formFEP Contact Form is a secure contact form to your WordPress site.This can be used with Front End PM or without.
Is FEP Contact Form Safe to Use in 2026?
Generally Safe
Score 85/100FEP Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The fep-contact-form plugin version 3.2 shows a generally good security posture, with strong adherence to modern WordPress security practices. The absence of known CVEs and a focus on prepared statements for SQL queries are positive indicators. However, the static analysis reveals potential areas of concern that warrant attention. A significant percentage of output escaping is not properly handled, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is displayed without proper sanitization. Furthermore, the taint analysis indicates four high-severity flows with unsanitized paths, suggesting that data entering the plugin might not be sufficiently validated before being used in potentially sensitive operations. While the attack surface appears well-protected with no direct unprotected entry points, the presence of unsanitized data flows is a critical risk that needs to be addressed. The lack of historical vulnerabilities is a strength, but it doesn't negate the immediate risks identified in the current analysis.
Key Concerns
- High severity unsanitized taint flows
- Low percentage of properly escaped output
FEP Contact Form Security Vulnerabilities
FEP Contact Form Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FEP Contact Form Attack Surface
Shortcodes 2
WordPress Hooks 44
Maintenance & Trust
FEP Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
FEP Contact Form Alternatives
ALIDANI Contact forms
alidani-contact-form
Contact form with visual form builder. Contact form that sends the data to email, to a database list and easy to update the content.
OweBest Contact Form
ob-contact-form
OweBest Contact form is a simple contact form which works out of the box. Use shortcode on posts or pages to generate OweBest Contact Form.
OB Contact Form to DB
ob-contact-form-to-db
OB Contact form to DB is an addon to OB Contact Form plugin, to stor all submitted entries into database and show them in back-end.
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
FEP Contact Form Developer Profile
6 plugins · 5K total installs
How We Detect FEP Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fep-contact-form/fepcf-script.js/wp-content/plugins/fep-contact-form/fepcf-admin-script.js/wp-content/plugins/fep-contact-form/fepcf-script.js/wp-content/plugins/fep-contact-form/fepcf-admin-script.jsfep-contact-form/fepcf-script.js?ver=fep-contact-form/fepcf-admin-script.js?ver=HTML / DOM Fingerprints
fepcf-options-tabledata-fepcf-noncefepcf_create_nonce