
FreeContactFormDotCom Security & Risk Analysis
wordpress.org/plugins/freecontactformdotcomA simple free contact form with text-based spam prevention.
Is FreeContactFormDotCom Safe to Use in 2026?
Generally Safe
Score 85/100FreeContactFormDotCom has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "freecontactformdotcom" v1.2 plugin exhibits a mixed security posture. On the positive side, the plugin has no recorded vulnerabilities (CVEs) and demonstrates good practices by utilizing prepared statements for all its SQL queries and performing at least one capability check. The absence of external HTTP requests and file operations further reduces its potential attack surface in those areas. However, a significant concern arises from the 0% output escaping, meaning all 13 outputs are potentially vulnerable to cross-site scripting (XSS) attacks. While the attack surface is small with only one shortcode entry point and no unprotected AJAX or REST API routes, the lack of output sanitization is a critical weakness. The taint analysis also shows no critical or high severity unsanitized flows, which is encouraging, but this is overshadowed by the broad output escaping deficiency. The vulnerability history being clear is a positive sign, suggesting that past development may have been secure, but it does not mitigate current code deficiencies.
Key Concerns
- 0% output escaping
- 0 nonce checks
FreeContactFormDotCom Security Vulnerabilities
FreeContactFormDotCom Release Timeline
FreeContactFormDotCom Code Analysis
Output Escaping
Data Flow Analysis
FreeContactFormDotCom Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
FreeContactFormDotCom Maintenance & Trust
Maintenance Signals
Community Trust
FreeContactFormDotCom Alternatives
CAPTCHA Solution
captcha-solution
CAPTCHA Solution is a CAPTCHA module intended to be called from other plugins. It is originally created for my Contact Form 7 plugin.
Simon's Simple Contact Form
simons-simple-contact-form
A lightweight WordPress contact form plugin with 18 themes, SMTP support, Google reCAPTCHA or internal captcha, and instant theme switching.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
contact-form-7-honeypot
Addons for Contact Form 7 — Honeypot, Database Entries, Redirection, Spam Protection, Webhooks, ACF integration for Contact Form 7, and more.
WP Armour – Honeypot Anti Spam
honeypot
Fastest growing Anti Spam plugin. No API calls, subscriptions, captcha or puzzle. Full GDPR complaint. For comments, contact form, login, registration
FreeContactFormDotCom Developer Profile
1 plugin · 10 total installs
How We Detect FreeContactFormDotCom
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/freecontactformdotcom/style.css/wp-content/plugins/freecontactformdotcom/freecontactformdotcom.phpfreecontactformdotcom/style.css?ver=HTML / DOM Fingerprints
wrapicon32form-tableregular-textbutton-primaryclearname="email_address_setting"name="spam_question_setting"name="spam_answer_setting"name="thankyou_setting"name="linkback_setting"value="Set"+6 morehas_idhas_name$$$valtrimfcfrequired+1 more[contact_form_here]