
Kento Ajax Contact Form Security & Risk Analysis
wordpress.org/plugins/kento-ajax-contact-formA simple contact form plugin using AJAX.
Is Kento Ajax Contact Form Safe to Use in 2026?
Generally Safe
Score 85/100Kento Ajax Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "kento-ajax-contact-form" plugin version 1.0 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by utilizing prepared statements for all SQL queries, properly escaping all output, and not performing file operations or external HTTP requests. There are also no recorded vulnerabilities in its history, suggesting a potentially stable and well-maintained codebase in the past. However, significant concerns arise from the attack surface. The plugin exposes two AJAX handlers without any authentication or capability checks, creating direct entry points for unauthenticated users. This lack of protection for critical functionalities is a notable weakness. Furthermore, the absence of nonce checks on these AJAX handlers compounds the risk, making them susceptible to Cross-Site Request Forgery (CSRF) attacks. While taint analysis and vulnerability history are clean, the active, unprotected AJAX endpoints represent a tangible and immediate security risk that should be addressed.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without nonce checks
Kento Ajax Contact Form Security Vulnerabilities
Kento Ajax Contact Form Release Timeline
Kento Ajax Contact Form Code Analysis
Output Escaping
Kento Ajax Contact Form Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Kento Ajax Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
Kento Ajax Contact Form Alternatives
Contact Form & SMTP Plugin for WordPress by PirateForms
pirate-forms
A simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
Contact Form Clean and Simple
clean-and-simple-contact-form-by-meg-nicholas
A clean and simple contact form with flexible CSS framework support.
Lite Contact Form
lite-contact-form
Lightweight and simple contact form with no additional user-unfriendly options. Can be additionally protected against spam by using Akismet and Google …
AKM Feedback Form
akm-feedback-form
Just insert the [AKMFORM] shortcode in pages of your WordPress site to display a simple and easy to use Feedback form.
Collect Lead Form
collect-lead-form
Collect Lead Form is a lightweight WordPress plugin to capture leads or use as an Ajax-powered contact form.
Kento Ajax Contact Form Developer Profile
22 plugins · 640 total installs
How We Detect Kento Ajax Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kento-ajax-contact-form/css/style.css/wp-content/plugins/kento-ajax-contact-form/js/kento-contact-form.js/wp-content/plugins/kento-ajax-contact-form/js/kento-contact-form.jskento-ajax-contact-form/css/style.css?ver=kento-ajax-contact-form/js/kento-contact-form.js?ver=HTML / DOM Fingerprints
kento-contact-form-name-validkento-contact-form-email-validkento-contact-form-email-emptykento-contact-form-mgs-validkento-contact-form-submitsending<!-- The Name form field --><!-- The Email form field --><!-- The mgs form field --><!-- The Submit button -->+1 moreid="kento-contact-form-name"id="kento-contact-form-email"id="kento-contact-form-mgs"id="kento-contact-form-submit"id="kento-contact-form-submit-success"kento_contact_form_ajaxurl<div id="kento-contact-form"><form name="myform" id="myform" method="POST"><table align="center"><tr>