
Mobile Only Contact Footer Security & Risk Analysis
wordpress.org/plugins/mobile-only-contact-footerAn editable, fixed position div that sticks to the bottom of web page on mobile devices.
Is Mobile Only Contact Footer Safe to Use in 2026?
Generally Safe
Score 85/100Mobile Only Contact Footer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mobile-only-contact-footer" plugin, version 1.0.0, exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-sum attack surface. Furthermore, the code signals indicate a healthy approach to security with no dangerous functions, all SQL queries using prepared statements, and no file operations or external HTTP requests. The absence of vulnerability history further reinforces this positive outlook.
However, a significant concern arises from the lack of capability checks and nonce checks. While the current attack surface is zero, any future development or changes that introduce new entry points without proper authentication and authorization mechanisms could expose the site to vulnerabilities. The output escaping, while partially effective with 61% proper escaping, still leaves a portion of outputs unescaped, which could be a vector for cross-site scripting (XSS) if user-supplied data is involved in those unescaped outputs. The taint analysis showing zero flows is reassuring, but the absence of checks leaves room for potential issues if new data flows are introduced.
In conclusion, the plugin demonstrates good initial security practices by minimizing its attack surface and employing safe coding techniques for its current functionality. The lack of any recorded vulnerabilities is a significant strength. Nevertheless, the absence of essential security checks like capability and nonce verification, alongside the incomplete output escaping, represents a latent risk that requires attention to maintain a secure application, especially if the plugin's functionality expands.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Partial output escaping (39% unescaped)
Mobile Only Contact Footer Security Vulnerabilities
Mobile Only Contact Footer Release Timeline
Mobile Only Contact Footer Code Analysis
Output Escaping
Mobile Only Contact Footer Attack Surface
WordPress Hooks 5
Maintenance & Trust
Mobile Only Contact Footer Maintenance & Trust
Maintenance Signals
Community Trust
Mobile Only Contact Footer Alternatives
Mobile Contact Line
mobile-contact-line
Simple plugin that allow you add mobile contact line to your wordpress site
LDW Mobile Contact Optimizer
ldw-mobile-contact-optimizer
Don’t waste any contact! Be reached in 1 click from mobile.
Contact Widgets For Elementor all the contact links you need in one place
contact-widgets-for-elementor
Contact Widgets For Elementor , Now you can add all the beast ways to contact you: Whatsapp, SMS, Facebook messenger, Email, Phone and Waze.
Mobile Contact Buttons
mobile-contact-buttons
Adds Call, Email and SMS buttons on bottom of website. Only for Mobile View of website.
Contact Info
contact-info
This plugin will allow you to add contact information from admin panel and show them in frontend. Using shortcodes and functions.
Mobile Only Contact Footer Developer Profile
1 plugin · 30 total installs
How We Detect Mobile Only Contact Footer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mobile-only-contact-footer/mobile_contact_footer.cssHTML / DOM Fingerprints
mcf_iconid="mobile-footer"