
Lana Contact Form Security & Risk Analysis
wordpress.org/plugins/lana-contact-formEasy to use contact form with captcha
Is Lana Contact Form Safe to Use in 2026?
Generally Safe
Score 85/100Lana Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lana-contact-form" plugin version 1.4.0 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a significant strength. The plugin also utilizes prepared statements for all SQL queries, which is a crucial security practice. The presence of nonce checks is also a positive sign. However, the analysis does highlight areas for improvement.
A concern arises from the moderate percentage of output escaping (70%), indicating that a portion of the plugin's output is not being properly sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without adequate escaping. The lack of capability checks on the single shortcode entry point is another area of potential weakness, as it suggests that any authenticated user could potentially trigger the shortcode's functionality without proper authorization.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the absence of critical or high-severity taint flows in the static analysis, suggests a low likelihood of severe, exploitable vulnerabilities being present. The strengths in areas like SQL handling and the clean vulnerability history are commendable. However, the unescaped output and the potential for unauthorized shortcode execution without capability checks represent the primary security concerns that warrant attention.
Key Concerns
- Unescaped output detected
- Missing capability checks on shortcode
Lana Contact Form Security Vulnerabilities
Lana Contact Form Code Analysis
Output Escaping
Lana Contact Form Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Lana Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
Lana Contact Form Alternatives
Spam protection, Honeypot, Anti-Spam by CleanTalk
cleantalk-spam-protect
Blocks spam comments, fake users, contact form spam and more. No impact on SEO. Privacy focused. CAPTCHA free, premium Antispam plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Contact Form 7 Captcha
contact-form-7-simple-recaptcha
Protect your Contact Form 7 forms with Google reCAPTCHA V2, Google reCAPTCHA V3, hCAPTCHA, or Cloudflare Turnstile.
Invisible reCaptcha for WordPress
invisible-recaptcha
Invisible reCaptcha for WordPress plugin helps you to protect your sites against bad spam bots using the new Invisible reCaptcha by Google.
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR)
contact-form-7-image-captcha
Adds an Image CAPTCHA to Contact Form 7 and WPForms, GDPR ready, perfect WPForms or Contact Form 7 Spam Protection Image CAPTCHA, adds a honeypot
Lana Contact Form Developer Profile
13 plugins · 4K total installs
How We Detect Lana Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lana-contact-form/assets/css/lana-contact-form.csslana-contact-form/assets/css/lana-contact-form.css?ver=HTML / DOM Fingerprints
lana-contact-formdata-bs-togglelana_contact_form[lana_contact_form]