OB Contact Form to DB Security & Risk Analysis

wordpress.org/plugins/ob-contact-form-to-db

OB Contact form to DB is an addon to OB Contact Form plugin, to stor all submitted entries into database and show them in back-end.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Aug 11, 2015
contact-formcontact-form-save-entriesemail-contact-formob-contact-formsimple-contact-form-to-db
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OB Contact Form to DB Safe to Use in 2026?

Generally Safe

Score 85/100

OB Contact Form to DB has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The static analysis of "ob-contact-form-to-db" v1.0 plugin shows an excellent initial security posture regarding its attack surface. There are no exposed AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the plugin's potential for external exploitation. Furthermore, the absence of dangerous function calls and external HTTP requests is commendable. However, the analysis does reveal areas of concern. A significant portion of SQL queries (33%) are not using prepared statements, posing a risk of SQL injection vulnerabilities. Additionally, a majority of output operations (62%) are not properly escaped, creating a strong potential for Cross-Site Scripting (XSS) attacks. The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the lack of nonces and capability checks in the static analysis, suggests a developer who may be prioritizing minimal functionality and potentially overlooking common WordPress security best practices. While the clean vulnerability history is a positive sign, the identified code signals point to significant inherent risks that could lead to future vulnerabilities if not addressed.

Key Concerns

  • SQL queries not using prepared statements
  • Output not properly escaped
  • Missing nonce checks
  • Missing capability checks
  • Bundled outdated library (DataTables v1.0.4)
Vulnerabilities
None known

OB Contact Form to DB Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

OB Contact Form to DB Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
8
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables1.0.4

SQL Query Safety

67% prepared3 total queries

Output Escaping

38% escaped13 total outputs
Attack Surface

OB Contact Form to DB Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_enqueue_scriptscontact-form-db.php:13
actionsave_obcfcontact-form-db.php:195
actionadmin_menucontact-form-db.php:231
Maintenance & Trust

OB Contact Form to DB Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedAug 11, 2015
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

OB Contact Form to DB Developer Profile

owebest

2 plugins · 20 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OB Contact Form to DB

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ob-contact-form-to-db/DataTables/media/js/jquery.dataTables.js/wp-content/plugins/ob-contact-form-to-db/DataTables/extensions/TableTools/js/dataTables.tableTools.js/wp-content/plugins/ob-contact-form-to-db/DataTables/syntax/shCore.js/wp-content/plugins/ob-contact-form-to-db/DataTables/js/demo.js/wp-content/plugins/ob-contact-form-to-db/DataTables/media/css/jquery.dataTables.css/wp-content/plugins/ob-contact-form-to-db/DataTables/extensions/TableTools/css/dataTables.tableTools.css/wp-content/plugins/ob-contact-form-to-db/DataTables/syntax/shCore.css/wp-content/plugins/ob-contact-form-to-db/DataTables/css/demo.css
Script Paths
/wp-content/plugins/ob-contact-form-to-db/DataTables/media/js/jquery.dataTables.js/wp-content/plugins/ob-contact-form-to-db/DataTables/extensions/TableTools/js/dataTables.tableTools.js/wp-content/plugins/ob-contact-form-to-db/DataTables/syntax/shCore.js/wp-content/plugins/ob-contact-form-to-db/DataTables/js/demo.js

HTML / DOM Fingerprints

CSS Classes
dataTables_wrapper
Data Attributes
data-page
JS Globals
DataTable
FAQ

Frequently Asked Questions about OB Contact Form to DB