
NM Contact Forms Security & Risk Analysis
wordpress.org/plugins/nm-contact-formsContact form plugin. NM contact forms allow you simple contact form integration with two built-in anti-spam solutions. Supports get variable.
Is NM Contact Forms Safe to Use in 2026?
Generally Safe
Score 85/100NM Contact Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The nm-contact-forms v2.0 plugin exhibits a mixed security posture. While it has a small attack surface and no recorded vulnerabilities or critical taint flows, there are significant concerns regarding output escaping and a lack of capability checks. The plugin's 100% unescaped output presents a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data displayed on the frontend is not being properly sanitized. The absence of capability checks is also a major weakness, potentially allowing unauthorized users to perform actions they shouldn't be able to. Despite the positive aspects like the absence of dangerous functions and the use of prepared statements for SQL queries, these critical oversight in output handling and access control greatly undermine the plugin's overall security. The lack of historical vulnerabilities is positive but doesn't mitigate the current, identified risks.
Key Concerns
- Output escaping: 0% properly escaped
- Capability checks: 0
NM Contact Forms Security Vulnerabilities
NM Contact Forms Code Analysis
Output Escaping
Data Flow Analysis
NM Contact Forms Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
NM Contact Forms Maintenance & Trust
Maintenance Signals
Community Trust
NM Contact Forms Alternatives
Contact Form by Supsystic
contact-form-by-supsystic
Contact Form Builder with drag-and-drop editor to create responsive, mobile ready contact forms in a second. Custom fields and contact form templates
DigitSix Simple Contact Form
digitsix-simple-contact-form
DigitSix Simple Contact Form is a simple solution for those who need simple contact forms for their website.
Contact Form Generator : Creative form builder for WordPress
contact-form-generator
Contact Form Generator is a creative and powerful contact form builder! You will get ready-to-use forms in 5 minutes!
Contact Form Monster
contact-form-monster
Contact form plugin is a simple contact form builder tool, which allows the user to create and edit different contact forms.
EngageBay Add-on For Contact Form 7
engagebay-add-on-for-contact-form-7
Send Contact Form 7 submissions to EngageBay automcatically using this plugin. Link any field type with EngageBay including custom fields.
NM Contact Forms Developer Profile
1 plugin · 200 total installs
How We Detect NM Contact Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nm-contact-forms/css/front.cssHTML / DOM Fingerprints
nm_hide[nm_forms