
Saksh Callback Request Form Security & Risk Analysis
wordpress.org/plugins/saksh-callback-request-formInspired by zerodha, Kotek Mahidra bank, JIO fibre lead generation form I setup this form it first ask users email ID and mobile number and then send …
Is Saksh Callback Request Form Safe to Use in 2026?
Generally Safe
Score 85/100Saksh Callback Request Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "saksh-callback-request-form" plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and properly escaping all output. It also has a clean vulnerability history with no known CVEs, suggesting a generally well-maintained codebase in that regard. The absence of file operations, external HTTP requests, and bundled libraries further reduces certain common attack vectors.
However, significant security concerns arise from its attack surface. With a total of 7 entry points, 6 of which are AJAX handlers, a critical weakness is the lack of authentication checks on all of these AJAX endpoints. This creates a substantial risk of unauthorized access and manipulation. The taint analysis further amplifies this concern, revealing 4 high-severity flows with unsanitized paths. While not explicitly categorized as critical or leading to direct code execution in the provided data, these unsanitized flows, especially in conjunction with the unprotected AJAX endpoints, present a clear pathway for potential vulnerabilities like Cross-Site Scripting (XSS) or other injection attacks if user-supplied data is not handled rigorously within these flows.
In conclusion, while the plugin excels in data handling and has a history of being free from known exploits, the unprotected AJAX endpoints combined with high-severity unsanitized taint flows represent a considerable risk. Addressing these specific areas of concern by implementing robust authentication and sanitization for all AJAX handlers is crucial to significantly improve its overall security.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Limited capability checks
Saksh Callback Request Form Security Vulnerabilities
Saksh Callback Request Form Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Saksh Callback Request Form Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Saksh Callback Request Form Maintenance & Trust
Maintenance Signals
Community Trust
Saksh Callback Request Form Alternatives
Contact Forms by Cimatti
contact-forms
Create and publish forms in your WordPress website with drag and drop. Contact forms, landing page forms, invitations, and more.
Lite Contact Form
lite-contact-form
Lightweight and simple contact form with no additional user-unfriendly options. Can be additionally protected against spam by using Akismet and Google …
Collect Lead Form
collect-lead-form
Collect Lead Form is a lightweight WordPress plugin to capture leads or use as an Ajax-powered contact form.
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
Contact Form & SMTP Plugin for WordPress by PirateForms
pirate-forms
A simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
Saksh Callback Request Form Developer Profile
14 plugins · 40 total installs
How We Detect Saksh Callback Request Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/saksh-callback-request-form/css/custom.css/wp-content/plugins/saksh-callback-request-form/js/custom.js/wp-content/plugins/saksh-callback-request-form/js/custom.jssaksh-callback-request-form/css/custom.css?ver=saksh-callback-request-form/js/custom.js?ver=HTML / DOM Fingerprints
ajaxurl[SakshCallbackRequestForm]