
Contact widget – Ocl.to Security & Risk Analysis
wordpress.org/plugins/ocl-widgetGenerate your own contact widget and paste it to your Wordpress page. Gather information about clients and automatically transfer it to your Ocl CRM s …
Is Contact widget – Ocl.to Safe to Use in 2026?
Generally Safe
Score 85/100Contact widget – Ocl.to has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ocl-widget" plugin v1.0.1 demonstrates a strong adherence to secure coding practices in several key areas. Notably, it has zero recorded vulnerabilities (CVEs) and no known security issues, suggesting a history of stable and potentially secure development. The static analysis also reveals a minimal attack surface with no AJAX handlers, REST API routes, shortcodes, or cron events exposed without proper checks. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests is a significant positive indicator.
However, there are notable areas of concern. The plugin's SQL queries are entirely unparameterized, presenting a significant risk of SQL injection vulnerabilities, especially as there are five such queries. While the plugin has one capability check, the absence of nonce checks on any potential entry points (though zero are explicitly listed) and the fact that only 75% of outputs are properly escaped leave room for cross-site scripting (XSS) vulnerabilities. The zero taint flows analyzed is not necessarily a positive sign; it could indicate that the taint analysis tooling was limited or that the plugin's code structure did not allow for comprehensive taint flow tracking.
In conclusion, while the plugin's lack of historical vulnerabilities and small attack surface are commendable, the unparameterized SQL queries and incomplete output escaping pose tangible risks. These are common vectors for severe vulnerabilities and require immediate attention. The plugin's security posture is mixed, with strengths in attack surface reduction and vulnerability history, but significant weaknesses in data handling and output sanitization.
Key Concerns
- SQL queries not using prepared statements
- Output escaping not fully implemented
- No nonce checks on entry points
Contact widget – Ocl.to Security Vulnerabilities
Contact widget – Ocl.to Code Analysis
SQL Query Safety
Output Escaping
Contact widget – Ocl.to Attack Surface
WordPress Hooks 5
Maintenance & Trust
Contact widget – Ocl.to Maintenance & Trust
Maintenance Signals
Community Trust
Contact widget – Ocl.to Alternatives
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Contact Form Widget
new-contact-form-widget
Create contact forms with query table management. Simple setup, secure submissions, and easy customization for your site.
Simple Contact Widget
simple-contact-widget
Creates the widget with contact information and map functionality.
Client Showcase
client-showcase
Display your Clients with pride. This plugin displays your client's logo in a page, post using a shortcode or use the custom widget.
Visitor Contact Forms
visitorcontact
Create customizable contact forms and sticky contact button for your WordPress blog. Web 2.0 style.
Contact widget – Ocl.to Developer Profile
2 plugins · 0 total installs
How We Detect Contact widget – Ocl.to
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ocl-widget/admin/css/style.css/wp-content/plugins/ocl-widget/admin/js/add-menu-script.jshttps://widget.clientlist.io/js/widget.min.jsocl-widget/admin/css/style.css?ver=ocl-widget/admin/js/add-menu-script.js?ver=HTML / DOM Fingerprints
ocl-widget-wrapperocl-widget-tabocl-widget-tab-nameocl-iframeocl-widget-closedata-ocl-widget-urldata-ocl-widget-idoclStartWidget