mamurjor simple contact form Security & Risk Analysis

wordpress.org/plugins/mamurjor-simple-contact-form

Just copy and paste this shortcode [mamurjor_contact_admin_without_mail] [mamurjor_contact_admin_mail]

0 active installs v1.0.0 PHP 7.0+ WP 3.0.1+ Updated Unknown
admincontactforminfoshow
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is mamurjor simple contact form Safe to Use in 2026?

Generally Safe

Score 100/100

mamurjor simple contact form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The mamurjor-simple-contact-form plugin version 1.0.0 presents a mixed security posture. On the positive side, it has a very small attack surface with only two shortcodes and no AJAX handlers or REST API routes, and importantly, none of its entry points appear to be unprotected from an initial assessment. The code also demonstrates good practices in output escaping, with 90% of outputs being properly handled, and no dangerous functions, file operations, or external HTTP requests were detected. The absence of any known vulnerabilities or CVEs in its history is also a strong indicator of responsible development and a relatively secure past.

However, significant concerns arise from the handling of SQL queries. All five detected SQL queries are executed without using prepared statements. This is a critical security weakness that exposes the plugin to potential SQL injection vulnerabilities. Furthermore, the complete lack of nonce checks and capability checks on its entry points, while mitigated somewhat by the small and seemingly protected attack surface, means that if any of these entry points were to become exposed or misused, there are no built-in safeguards to verify user intent or authorization. The absence of taint analysis flows is noted, but this could be due to the limited complexity of the plugin or the analysis tools used, and doesn't negate the identified risks.

In conclusion, while mamurjor-simple-contact-form 1.0.0 exhibits strengths in avoiding common pitfalls like unescaped output and dangerous functions, the pervasive use of raw SQL queries without prepared statements is a major vulnerability that significantly elevates the risk profile. The lack of nonce and capability checks, while not immediately exploitable due to the limited attack surface, represents a weakness that could be exploited if the plugin's context changes or if other vulnerabilities are introduced. This plugin requires immediate attention to address the SQL injection risk.

Key Concerns

  • Raw SQL queries without prepared statements
  • No nonce checks on entry points
  • No capability checks on entry points
  • Limited output escaping (90%)
Vulnerabilities
None known

mamurjor simple contact form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

mamurjor simple contact form Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
0 prepared
Unescaped Output
1
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared5 total queries

Output Escaping

90% escaped10 total outputs
Attack Surface

mamurjor simple contact form Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[mamurjor_contact_admin_without_mail] admin\adminwithoutmail.php:27
[mamurjor_contact_admin_mail] admin\index.php:42
WordPress Hooks 6
actionadmin_menuadmin\search.php:6
actionplugins_loadedincludes\class-mamurjor_simple_contact_form.php:142
actionadmin_enqueue_scriptsincludes\class-mamurjor_simple_contact_form.php:157
actionadmin_enqueue_scriptsincludes\class-mamurjor_simple_contact_form.php:158
actionwp_enqueue_scriptsincludes\class-mamurjor_simple_contact_form.php:173
actionwp_enqueue_scriptsincludes\class-mamurjor_simple_contact_form.php:174
Maintenance & Trust

mamurjor simple contact form Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedUnknown
PHP min version7.0
Downloads901

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

mamurjor simple contact form Developer Profile

Mamurjor IT

6 plugins · 20 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect mamurjor simple contact form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mamurjor-simple-contact-form/css/mamurjor_simple_contact_form-admin.css/wp-content/plugins/mamurjor-simple-contact-form/js/mamurjor_simple_contact_form-admin.js
Version Parameters
mamurjor_simple_contact_form-admin.css?ver=mamurjor_simple_contact_form-admin.js?ver=

HTML / DOM Fingerprints

Shortcode Output
[mamurjor_contact_shorcode]
FAQ

Frequently Asked Questions about mamurjor simple contact form