Instant Contact – Generate leads and convert them into Customers Security & Risk Analysis

wordpress.org/plugins/instant-contact

Instant Contact - supports all cf7, gravity forms, and form embedments...

10 active installs v1.0 PHP + WP 3.7+ Updated Oct 19, 2016
cf7chat-boxgravity-formsquick-chatthird-party-embedments
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Instant Contact – Generate leads and convert them into Customers Safe to Use in 2026?

Generally Safe

Score 85/100

Instant Contact – Generate leads and convert them into Customers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "instant-contact" plugin v1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified attack surface points, such as unprotected AJAX handlers, REST API routes, shortcodes, or cron events, significantly limits the plugin's exposure to external exploitation. Furthermore, the code shows good practices regarding SQL queries, exclusively using prepared statements, and a high percentage of output is properly escaped, mitigating common cross-site scripting (XSS) risks. The lack of file operations and external HTTP requests also reduces potential attack vectors.

Despite these positive indicators, the analysis reveals some areas of concern. The complete absence of nonce checks and capability checks is a notable weakness. While the current attack surface might be minimal, this leaves the plugin vulnerable if new entry points are introduced or if existing code is modified in the future without proper authorization and validation. The taint analysis, while reporting no flows, might be incomplete if the analysis itself was limited in scope. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign, suggesting it has not been a target or has maintained good security over time. However, the lack of historical data also means there isn't a proven track record of proactive vulnerability management.

In conclusion, "instant-contact" v1.0 demonstrates good foundational security by minimizing its attack surface and employing secure coding practices for data handling and output. However, the complete reliance on the absence of entry points, rather than implementing robust authorization and integrity checks, presents a latent risk. The lack of historical vulnerability data provides reassurance but no definitive guarantee of future security. The plugin is likely secure in its current state but could be significantly more resilient with the addition of essential security checks.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Low coverage of taint analysis
Vulnerabilities
None known

Instant Contact – Generate leads and convert them into Customers Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Instant Contact – Generate leads and convert them into Customers Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
21 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped24 total outputs
Attack Surface

Instant Contact – Generate leads and convert them into Customers Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuinstant-contact.php:24
actionadmin_enqueue_scriptsinstant-contact.php:25
actionwp_footerinstant-contact.php:27
actionwp_enqueue_scriptsinstant-contact.php:28
actionwp_print_stylesinstant-contact.php:29
actionwp_enqueue_scriptsinstant-contact.php:30
actionwp_footerinstant-contact.php:31
Maintenance & Trust

Instant Contact – Generate leads and convert them into Customers Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedOct 19, 2016
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Instant Contact – Generate leads and convert them into Customers Developer Profile

faisaliefr

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Instant Contact – Generate leads and convert them into Customers

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/instant-contact/css/options.css/wp-content/plugins/instant-contact/js/options.js/wp-content/plugins/instant-contact/css/output.css
Script Paths
/wp-content/plugins/instant-contact/js/options.js

HTML / DOM Fingerprints

JS Globals
instantContact_cssinstantContact_js
FAQ

Frequently Asked Questions about Instant Contact – Generate leads and convert them into Customers