
mamurjor simple contact form Security & Risk Analysis
wordpress.org/plugins/mamurjor-simple-contact-formJust copy and paste this shortcode [mamurjor_contact_admin_without_mail] [mamurjor_contact_admin_mail]
Is mamurjor simple contact form Safe to Use in 2026?
Generally Safe
Score 100/100mamurjor simple contact form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mamurjor-simple-contact-form plugin version 1.0.0 presents a mixed security posture. On the positive side, it has a very small attack surface with only two shortcodes and no AJAX handlers or REST API routes, and importantly, none of its entry points appear to be unprotected from an initial assessment. The code also demonstrates good practices in output escaping, with 90% of outputs being properly handled, and no dangerous functions, file operations, or external HTTP requests were detected. The absence of any known vulnerabilities or CVEs in its history is also a strong indicator of responsible development and a relatively secure past.
However, significant concerns arise from the handling of SQL queries. All five detected SQL queries are executed without using prepared statements. This is a critical security weakness that exposes the plugin to potential SQL injection vulnerabilities. Furthermore, the complete lack of nonce checks and capability checks on its entry points, while mitigated somewhat by the small and seemingly protected attack surface, means that if any of these entry points were to become exposed or misused, there are no built-in safeguards to verify user intent or authorization. The absence of taint analysis flows is noted, but this could be due to the limited complexity of the plugin or the analysis tools used, and doesn't negate the identified risks.
In conclusion, while mamurjor-simple-contact-form 1.0.0 exhibits strengths in avoiding common pitfalls like unescaped output and dangerous functions, the pervasive use of raw SQL queries without prepared statements is a major vulnerability that significantly elevates the risk profile. The lack of nonce and capability checks, while not immediately exploitable due to the limited attack surface, represents a weakness that could be exploited if the plugin's context changes or if other vulnerabilities are introduced. This plugin requires immediate attention to address the SQL injection risk.
Key Concerns
- Raw SQL queries without prepared statements
- No nonce checks on entry points
- No capability checks on entry points
- Limited output escaping (90%)
mamurjor simple contact form Security Vulnerabilities
mamurjor simple contact form Code Analysis
SQL Query Safety
Output Escaping
mamurjor simple contact form Attack Surface
Shortcodes 2
WordPress Hooks 6
Maintenance & Trust
mamurjor simple contact form Maintenance & Trust
Maintenance Signals
Community Trust
mamurjor simple contact form Alternatives
Lead info with country for Contact Form 7
contact-form-7-lead-info-with-country
Lead info with country for Contact Form 7 helps to track users that fill in forms.
Contact Information Widget
contact-information-widget
Easily add a Contact Information Widget to your widgetable sidebar. With this plugin you can add a contact information.
Contact Form 7 Get and Show Parameter from URL
contact-form-7-get-and-show-parameter-from-url
Get or show parameters from the URL directly within the Contact Form 7 plugin
Widget Contact Now
widget-contact-now
Add contact information quickly and easily with ready-made labels. Display gorgeous contact information on your website with simple, easy-to-use widge …
Contact Information Widget
simple-contact-information-widget
Contact Information Widget.
mamurjor simple contact form Developer Profile
6 plugins · 20 total installs
How We Detect mamurjor simple contact form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mamurjor-simple-contact-form/css/mamurjor_simple_contact_form-admin.css/wp-content/plugins/mamurjor-simple-contact-form/js/mamurjor_simple_contact_form-admin.jsmamurjor_simple_contact_form-admin.css?ver=mamurjor_simple_contact_form-admin.js?ver=HTML / DOM Fingerprints
[mamurjor_contact_shorcode]