
GM Contact Form Security & Risk Analysis
wordpress.org/plugins/gm-contact-formA simple foolproof contact form for WordPress.
Is GM Contact Form Safe to Use in 2026?
Generally Safe
Score 85/100GM Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'gm-contact-form' plugin v1.0 presents a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and has no recorded vulnerability history, there are significant concerns stemming from its attack surface and output handling. The presence of two AJAX handlers without authentication checks represents a direct pathway for potential unauthorized actions or data manipulation. Furthermore, the complete lack of output escaping is a critical flaw, leaving the plugin highly susceptible to cross-site scripting (XSS) vulnerabilities, where malicious code could be injected and executed in the context of a user's browser. The taint analysis, while showing no critical or high severity flows, did indicate unsanitized paths, which, when combined with unescaped output, could still lead to exploitable conditions. Overall, the plugin's lack of robust input validation and output sanitization, particularly for its unprotected entry points, outweighs its positive attributes, making it a notable security risk.
Key Concerns
- AJAX handlers without authentication checks
- Output escaping not implemented
- No nonce checks on AJAX
- Flows with unsanitized paths (from Taint Analysis)
GM Contact Form Security Vulnerabilities
GM Contact Form Code Analysis
Output Escaping
Data Flow Analysis
GM Contact Form Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
GM Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
GM Contact Form Alternatives
Contact Form X
contact-form-x
Displays a user-friendly contact form that your visitors will love. Lightweight, fast, secure, and accessible (ADA/WCAG compliant).
Ajax Simple Contact Form
ajax-simplecontact-form
This is a simple and customizable wordpress ajax contact form.
Contact Form 7: Support Deprecated Settings
cf7-support-deprecated-settings
Provide continued support for on_sent_ok and on_submit within Contact Form 7's Additional Settings
ChiliForms
chiliforms
Easy to use drag-n-drop contact form builder plugin for your blog or website.
Contact Dialog
contact-dialog
Enables display of an AJAX driven contact form when a user clicks on links with a specified class.
GM Contact Form Developer Profile
2 plugins · 0 total installs
How We Detect GM Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gm-contact-form/css/gm-contact.css/wp-content/plugins/gm-contact-form/js/gm-contact.js/wp-content/plugins/gm-contact-form/js/gm-contact.jsgm-contact-form/css/gm-contact.css?ver=gm-contact-form/js/gm-contact.js?ver=HTML / DOM Fingerprints
gm_contact