Flagged Phone Field Security & Risk Analysis

wordpress.org/plugins/flagged-phone-field

The Flagged Phone Field plugin is a powerful tool designed for WordPress, offering advanced customization for phone number fields.

0 active installs v1.0.1 PHP 7.4+ WP 6.3+ Updated Unknown
gravityformsinternational-phone-inputphone-fieldphone-validationsmart-phone-field
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Flagged Phone Field Safe to Use in 2026?

Generally Safe

Score 100/100

Flagged Phone Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The flagged-phone-field plugin v1.0.1 exhibits an excellent static security posture. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength. Furthermore, the code demonstrates robust security practices with 100% of SQL queries using prepared statements and 99% of output properly escaped. The lack of dangerous functions, file operations, external HTTP requests, and the presence of bundled libraries like Select2 and jQuery are also positive indicators. Taint analysis shows a low number of flows, with none flagged as critical or high severity.

The vulnerability history for this plugin is completely clean, with no known CVEs recorded. This suggests a history of well-maintained and secure code, or at least no publicly disclosed vulnerabilities. While the current analysis shows no immediate exploitable flaws, the complete lack of nonce and capability checks across all entry points (even though there are no entry points identified in the static analysis) is a potential concern if the plugin were to evolve and introduce new functionalities that might create new entry points. The bundled libraries, while common, should still be monitored for known vulnerabilities, though none are indicated here.

In conclusion, flagged-phone-field v1.0.1 appears to be a very secure plugin based on the provided static analysis and vulnerability history. Its minimal attack surface and strong coding practices are commendable. The only theoretical weakness lies in the complete absence of explicit security checks like nonces and capability checks, which could become a concern if the plugin's functionality were to expand without careful consideration of these security measures. However, based solely on the current data, the risk is extremely low.

Vulnerabilities
None known

Flagged Phone Field Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Flagged Phone Field Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
72 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
2

Bundled Libraries

Select2jQuery

Output Escaping

99% escaped73 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
wpfpf_settings_page (includes\class-wpfpf-settings.php:128)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Flagged Phone Field Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menuincludes\class-wpfpf-settings.php:58
actionadmin_enqueue_scriptsincludes\class-wpfpf-settings.php:59
actionwpfpf_settings_contentincludes\class-wpfpf-settings.php:60
actionwpfpf_php_config_contentincludes\class-wpfpf-settings.php:61
actionwpfpf_about_us_contentincludes\class-wpfpf-settings.php:62
filtergform_field_contentpublic\class-gravity-forms.php:11
actiongform_enqueue_scriptspublic\class-gravity-forms.php:12
filtergform_field_css_classpublic\class-gravity-forms.php:13
Maintenance & Trust

Flagged Phone Field Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.4
Downloads409

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Flagged Phone Field Developer Profile

BrainFleck Solutions

4 plugins · 280 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Flagged Phone Field

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flagged-phone-field/assets/css/wpfpf-style.css/wp-content/plugins/flagged-phone-field/assets/css/select2.min.css/wp-content/plugins/flagged-phone-field/assets/js/wpfpf-scripts.js/wp-content/plugins/flagged-phone-field/assets/js/select2.min.js
Script Paths
/wp-content/plugins/flagged-phone-field/assets/js/wpfpf-scripts.js/wp-content/plugins/flagged-phone-field/assets/js/select2.min.js
Version Parameters
wpfpf-style-adminwpfpf-select-2-adminwpfpf-analytics-scriptwpfpf-select-2

HTML / DOM Fingerprints

CSS Classes
wpfpf-style-adminwpfpf-select-2-adminwpfpf-analytics-scriptwpfpf-select-2
JS Globals
WPFPF_PLUGIN_URLWPFPF_VERSIONWPFPF_TEMPLATE_PATHWPFPF_PLUGIN_PATHWPFPF_MAIN_FILEWPFPF_ABSPATH+6 more
FAQ

Frequently Asked Questions about Flagged Phone Field