
MangoFp Security & Risk Analysis
wordpress.org/plugins/mangofpManage Contact Form 7 messages directly in WordPress like leads in the CRM system.
Is MangoFp Safe to Use in 2026?
Generally Safe
Score 100/100MangoFp has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis, the "mangofp" v1.0.0 plugin presents a seemingly strong security posture with no identified critical vulnerabilities in its code. The absence of an attack surface through AJAX handlers, REST API routes, shortcodes, or cron events significantly reduces potential entry points for attackers. Furthermore, the plugin demonstrates good practices by utilizing prepared statements for 85% of its SQL queries and avoiding dangerous functions, file operations, and external HTTP requests. The vulnerability history being clear of any recorded CVEs further reinforces this positive impression, suggesting a well-maintained or recently developed plugin without known exploitable flaws.
However, a closer examination reveals areas for concern. The limited output escaping (only 50% properly escaped for 2 outputs) presents a risk of cross-site scripting (XSS) vulnerabilities if the unescaped outputs are user-controlled or contain dynamic data. The presence of only one capability check, while the total entry points are zero, is unusual and could indicate a lack of necessary access controls if any entry points were to be discovered in future versions or through other means. The zero taint analysis flows is also notable, as it might mean the analysis was limited or that there were no detectable sensitive data flows. While the plugin currently appears secure, the aforementioned areas of concern warrant attention to ensure robust security in the long term.
Key Concerns
- Half of outputs are not properly escaped
- Only one capability check present
MangoFp Security Vulnerabilities
MangoFp Code Analysis
SQL Query Safety
Output Escaping
MangoFp Attack Surface
WordPress Hooks 7
Maintenance & Trust
MangoFp Maintenance & Trust
Maintenance Signals
Community Trust
MangoFp Alternatives
Contact Form 7 – SalesKing CRM Addon
contact-form-7-salesking-crm-addon
Get your Contact Form 7 data straight into SalesKing CRM.
Juridic-OS Connector
juridic-os-connector
El plugin oficial de Juridic-OS para integración de formularios de contacto con sistemas de gestión legal.
WorkZen Connector
workzen-connector
Connect your WordPress forms to WorkZen CRM and never miss a lead again.
AFI – The Easiest Integration Plugin
advanced-form-integration
Connect any WordPress form or event to 200+ apps — no code. Send leads, orders, and signups to your CRM, email, or sheets in minutes.
Lenix Leads Collector
lenix-elementor-leads-addon
Leads Collector, Collects forms entries from Elementor,Cf7,WPForms and more with export to CSV.
MangoFp Developer Profile
1 plugin · 0 total installs
How We Detect MangoFp
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mangofp/assets/js/chunk-vendors.js/wp-content/plugins/mangofp/assets/js/app.js/wp-content/plugins/mangofp/assets/css/chunk-vendors.css/wp-content/plugins/mangofp/assets/css/app.csshttp://localhost:8080/js/chunk-vendors.jshttp://localhost:8080/js/app.jshttp://localhost:3000/js/chunk-vendors.jshttp://localhost:3000/js/app.jsmangofp/assets/js/chunk-vendors.js?ver=mangofp/assets/js/app.js?ver=mangofp/assets/css/chunk-vendors.css?ver=mangofp/assets/css/app.css?ver=HTML / DOM Fingerprints
MANGOFP_RESOURCES/wp-json/mangofp/v1/labels/wp-json/mangofp/v1/templates/wp-json/mangofp/v1/templates/(?P<templateCode>[a-zA-Z0-9-]+)/wp-json/mangofp/v1/messages/wp-json/mangofp/v1/test2/wp-json/mangofp/v1/messages/(?P<uuid>[a-zA-Z0-9-]+)/emails/wp-json/mangofp/v1/messages/(?P<uuid>[a-zA-Z0-9-]+)/wp-json/mangofp/v1/messages/(?P<uuid>[a-zA-Z0-9-]+)/history/(?P<historyItemId>[^ /]+)/wp-json/mangofp/v1/attachments/wp-json/mangofp/v1/steps/wp-json/mangofp/v1/steps/(?P<code>[a-zA-Z0-9-]+)<div id="app"></div>