
Lite Contact Form Security & Risk Analysis
wordpress.org/plugins/lite-contact-formLightweight and simple contact form with no additional user-unfriendly options. Can be additionally protected against spam by using Akismet and Google …
Is Lite Contact Form Safe to Use in 2026?
Generally Safe
Score 85/100Lite Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lite-contact-form" v1.1.6 plugin exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are positive indicators. Furthermore, all identified output points are properly escaped, and there is no recorded vulnerability history, suggesting a well-maintained and secure plugin. However, a significant concern arises from the presence of one unprotected REST API route, which represents a direct entry point into the application without any authentication or authorization checks. This could potentially be exploited by attackers to perform unintended actions or gain unauthorized access to data if the route's functionality is sensitive.
The static analysis highlights one unprotected REST API route as the primary security concern, contributing to a notable attack surface that lacks proper authorization. While the plugin demonstrates strong adherence to secure coding practices in other areas, this single unprotected entry point is a critical weakness. The absence of any recorded vulnerabilities in its history is a positive sign, but it does not negate the risk posed by the identified unprotected REST API endpoint. A balanced view shows a plugin with good internal coding but a critical external exposure that needs immediate attention.
Key Concerns
- Unprotected REST API route
Lite Contact Form Security Vulnerabilities
Lite Contact Form Code Analysis
Output Escaping
Lite Contact Form Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Lite Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
Lite Contact Form Alternatives
Saksh Callback Request Form
saksh-callback-request-form
Inspired by zerodha, Kotek Mahidra bank, JIO fibre lead generation form I setup this form it first ask users email ID and mobile number and then send …
Contact Form & SMTP Plugin for WordPress by PirateForms
pirate-forms
A simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
Contact Form Clean and Simple
clean-and-simple-contact-form-by-meg-nicholas
A clean and simple contact form with flexible CSS framework support.
More Mails for CF7
more-mails-for-cf7
Extends the ubiquitous Contact Form 7 plugin to allow three or more messages.
Contact Form 7 Countries
cf7-countries
Country drop-down menu for Contact Form 7.
Lite Contact Form Developer Profile
7 plugins · 420 total installs
How We Detect Lite Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lite-contact-form/css/style.min.css/wp-content/plugins/lite-contact-form/js/js.lite-contact-form.min.jslite-contact-form/js/js.lite-contact-form.min.jslite-contact-form/css/style.min.css?ver=js.lite-contact-form.min.js?ver=HTML / DOM Fingerprints
lcflcf-validatelcf-tiplcf-spinnerdata-lcf-idlcf/wp-json/lite-contact-form/v1/submit<form class="lcf" method="post" onsubmit="return false"><input type="hidden" name="_lcf" value="