
ScuolaSemplice Contacts Security & Risk Analysis
wordpress.org/plugins/scuolasemplice-contactsPlugin that allows you to publish contact forms to acquire leads and student data that will be automatically imported into the ScuolaSemplice software
Is ScuolaSemplice Contacts Safe to Use in 2026?
Generally Safe
Score 92/100ScuolaSemplice Contacts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The scuolasemplice-contacts plugin v1.7 exhibits a concerning security posture due to a significant number of unprotected AJAX handlers. With 8 out of 8 AJAX handlers lacking authentication checks, this presents a substantial attack surface, making it highly vulnerable to unauthorized actions. The taint analysis further highlights this risk, with all 12 analyzed flows having unsanitized paths, including 10 of high severity. This indicates a high likelihood of code injection or data manipulation vulnerabilities being exploitable through these flows.
While the plugin shows some good practices like a relatively high percentage of prepared statements for SQL queries and a decent amount of output escaping, these strengths are heavily overshadowed by the critical lack of authorization on AJAX endpoints and the pervasive taint issues. The absence of any recorded CVEs is a positive sign, suggesting the plugin might not have been widely targeted or previously vulnerable. However, the current static analysis reveals significant weaknesses that could easily lead to exploitable vulnerabilities. The plugin's overall security is thus compromised by these critical oversights, demanding immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths (High severity)
- Dangerous function: unserialize
- No nonce checks
- Bundled outdated library: DataTables v1.10.20
ScuolaSemplice Contacts Security Vulnerabilities
ScuolaSemplice Contacts Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
ScuolaSemplice Contacts Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 13
Scheduled Events 1
Maintenance & Trust
ScuolaSemplice Contacts Maintenance & Trust
Maintenance Signals
Community Trust
ScuolaSemplice Contacts Alternatives
Lenix Leads Collector
lenix-elementor-leads-addon
Leads Collector, Collects forms entries from Elementor,Cf7,WPForms and more with export to CSV.
LeadSnap
leadsnap
Save the leads to our lead management system CRM generated by Contact Form 7
CRM and Lead Management by vcita
crm-customer-relationship-management-by-vcita
CRM for WordPress: a powerful, all-in-one client management tool that will help you keep your clients close and create long-lasting customer relations …
Wise Agent Lead Forms
wiseagentleadform
Short Description: The Wise Agent WordPress plugin lets you easily add capture forms to any page on your WordPress site.
Sprout Clients – CRM and Lead Management
sprout-clients
Properly leveraging your contact lists isn’t sending out a single email to the entire list asking for work — instead you need to build business relati …
ScuolaSemplice Contacts Developer Profile
1 plugin · 20 total installs
How We Detect ScuolaSemplice Contacts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scuolasemplice-contacts/css//wp-content/plugins/scuolasemplice-contacts/js/