
Reach Me Security & Risk Analysis
wordpress.org/plugins/reach-meReach Me is a simple, yet powerful plugin that allows you to display your contact information anywhere on your website.
Is Reach Me Safe to Use in 2026?
Generally Safe
Score 85/100Reach Me has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "reach-me" plugin version 1.0.7 exhibits a concerning security posture due to several critical code analysis findings, despite a clean vulnerability history. While the plugin presents a seemingly small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, the internal code practices raise significant red flags. The static analysis reveals a complete lack of prepared statements for its SQL queries and a 0% rate for properly escaped output, indicating a high likelihood of SQL injection and cross-site scripting (XSS) vulnerabilities. Furthermore, the absence of nonce and capability checks means that any unintended entry points, if they were to be discovered or introduced in future versions, would be unprotected.
The taint analysis, while not flagging critical or high severity flows, did identify two flows with unsanitized paths. When combined with the unescaped output, this suggests that user-supplied data could potentially be used in file operations or other sensitive contexts without proper sanitization, which could lead to unexpected behavior or security issues if not handled with extreme care. The plugin's history of zero known vulnerabilities might create a false sense of security, but the current code analysis strongly suggests that underlying vulnerabilities likely exist and have not yet been exploited or discovered. The complete lack of security best practices in data handling (SQL, output, taint) is a major weakness that outweighs the small attack surface. Immediate attention is required to address these code-level deficiencies.
Key Concerns
- SQL queries without prepared statements
- 0% output escaping
- Flows with unsanitized paths
- No nonce checks
- No capability checks
Reach Me Security Vulnerabilities
Reach Me Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Reach Me Attack Surface
WordPress Hooks 6
Maintenance & Trust
Reach Me Maintenance & Trust
Maintenance Signals
Community Trust
Reach Me Alternatives
Personal Contact Info Widget
personal-contact-info-widget
Add a custom Widget to display your profile photo, social media links and contact information.
Contact Us Page
contact-us-page
Create your contact page in seconds with a contact form, map, social icons and your contact info.
Naibabiji Global Connect Hub
naibabiji-global-connect-hub
Provides a unified contact channel management and display system for your entire site, including a reusable floating contact center.
Company Data Manager
company-data-manager
A plugin for managing and displaying essential company information, including contact details and social media links.
Powerkit – Supercharge your WordPress Site
powerkit
Essential components for every WordPress site: share buttons, social links, social media integrations, galleries, lazyload, custom widgets, and more.
Reach Me Developer Profile
3 plugins · 7K total installs
How We Detect Reach Me
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/reach-me/fonts/font-awesome-4.7.0/css/font-awesome.min.cssreach-me/fonts/font-awesome-4.7.0/css/font-awesome.min.css?ver=4.7.0