
Front End PM Security & Risk Analysis
wordpress.org/plugins/front-end-pmFront End PM is a Private Messaging system and a secure contact form to your WordPress site.This is full functioning messaging system from front end.
Is Front End PM Safe to Use in 2026?
Generally Safe
Score 92/100Front End PM has a strong security track record. Known vulnerabilities have been patched promptly.
The plugin "front-end-pm" v11.4.5 exhibits a generally good security posture with a low attack surface and a significant number of protected entry points. The static analysis reveals a reasonable implementation of security best practices, including the use of prepared statements for a majority of SQL queries and a decent percentage of properly escaped output. The absence of dangerous functions and external HTTP requests are positive indicators.
However, there are areas of concern. The taint analysis identified two flows with unsanitized paths, which, while not reaching critical or high severity in this instance, represent a potential for vulnerabilities if exploited. The presence of file operations, even without explicit detail, warrants attention as it can be an avenue for attacks. The plugin's vulnerability history, though currently clear of unpatched issues, includes a past medium-severity CVE for "Exposure of Sensitive Information to an Unauthorized Actor." This suggests that while the developers have addressed past issues, the potential for such vulnerabilities may exist.
Overall, the plugin has strengths in its controlled attack surface and implementation of core security features. However, the identified unsanitized paths in the taint analysis and the historical vulnerability pattern necessitate ongoing vigilance. Developers should prioritize addressing the unsanitized paths and continue to rigorously audit code for potential information exposure risks.
Key Concerns
- Flows with unsanitized paths found in taint analysis
- SQL queries not using prepared statements
- Output not properly escaped
- Past medium severity vulnerability
- Bundled Freemius library v1.0
Front End PM Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Front End PM < 11.4.3 - Sensitive Information Exposure via Directory Listing
Front End PM Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Front End PM Attack Surface
AJAX Handlers 4
Shortcodes 5
WordPress Hooks 120
Maintenance & Trust
Front End PM Maintenance & Trust
Maintenance Signals
Community Trust
Front End PM Alternatives
Better Messages – Live Chat, Chat Rooms, Real-Time Messaging & Private Messages
bp-better-messages
Real-time messaging and chat rooms for WordPress ecosystem: private conversations, public and private chat rooms, video & audio calls, and more.
BuddyPress Messaging Control
bp-messaging-control
This plugin is a Swiss Army Knife for messaging, It allows the site admin to place restrictions on public and private messages including general rules …
BuddyPress Restrict Messages
buddypress-restrict-messages
This plugin allows the site admin to restrict who can send private messages or to enable the users to choose themselves.
Cloudburst Messenger Bubbles
cloudburst-messenger-bubbles
Adds a clean, easy-to-use "Messenger Bubble" block to represent chat conversations.
Facebook Chat Plugin – Live Chat Plugin for WordPress
facebook-messenger-customer-chat
The Facebook Chat Plugin makes it easy for your website visitors to chat with you and ask you questions, even if they don't have Messenger.
Front End PM Developer Profile
6 plugins · 5K total installs
How We Detect Front End PM
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/front-end-pm/assets/js/admin.js/wp-content/plugins/front-end-pm/assets/css/admin.css/wp-content/plugins/front-end-pm/assets/css/fep.css/wp-content/plugins/front-end-pm/assets/css/bootstrap.min.css/wp-content/plugins/front-end-pm/assets/css/font-awesome.min.css/wp-content/plugins/front-end-pm/assets/js/admin.jsfront-end-pm/assets/js/admin.js?ver=front-end-pm/assets/css/admin.css?ver=front-end-pm/assets/css/fep.css?ver=front-end-pm/assets/css/bootstrap.min.css?ver=front-end-pm/assets/css/font-awesome.min.css?ver=HTML / DOM Fingerprints
fep-contentfep-message-listfep-message-formfep-field-wrapperfep-message-subjectfep-message-datefep-message-sender-avatarfep-message-sender-name+18 more<!-- Do NOT Close the Div --><!-- Do Close the Div -->data-fep-recipientdata-fep-subjectdata-fep-messagedata-fep-attachmentfep_adminFEP_MAIN/wp-json/fep/v1/messages/wp-json/fep/v1/message/wp-json/fep/v1/send[front-end-pm][fep_messages][fep_compose_form][fep_message_form]