
Simple Coherent Form Security & Risk Analysis
wordpress.org/plugins/simple-coherent-formA simple plugin to create coherent inputs between themes and plugins. Light, efficient, accessible and compatible with CF7. Best for developers.
Is Simple Coherent Form Safe to Use in 2026?
Generally Safe
Score 100/100Simple Coherent Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-coherent-form" v2.4.11 plugin demonstrates generally good security practices with a strong emphasis on prepared SQL statements and proper output escaping. The absence of known vulnerabilities in its history is a positive indicator of past security diligence. However, a significant concern arises from the static analysis, specifically the presence of 4 AJAX handlers that lack authentication checks. This creates a substantial attack surface that could be exploited by unauthenticated users to trigger potentially sensitive actions within the plugin.
The code analysis does not reveal any critical or high-severity taint flows, nor does it flag dangerous functions or raw SQL queries, which are all positive signs. The file operations and external HTTP requests are also not flagged as immediate risks based on this data. The limited number of cron events is also not a significant concern. The main weakness lies in the exposed AJAX endpoints, which could be a primary vector for exploitation if any of those handlers perform actions that could be misused without proper authorization.
In conclusion, while the plugin benefits from robust SQL and output sanitization and has a clean vulnerability history, the unprotected AJAX endpoints represent a clear and present risk. Addressing these unprotected entry points should be the highest priority to improve the plugin's security posture and mitigate potential unauthorized access or manipulation.
Key Concerns
- Unprotected AJAX handlers
Simple Coherent Form Security Vulnerabilities
Simple Coherent Form Code Analysis
Output Escaping
Simple Coherent Form Attack Surface
AJAX Handlers 12
WordPress Hooks 121
Scheduled Events 3
Maintenance & Trust
Simple Coherent Form Maintenance & Trust
Maintenance Signals
Community Trust
Simple Coherent Form Alternatives
Country & Phone Field Contact Form 7
country-phone-field-contact-form-7
Add country drop down with flags and phone number with country phone extension fields in contact form 7.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Styler Mate for Contact Form 7
cf7-styler-for-divi
Style and enhance Contact Form 7 for Divi, Bricks, Elementor, Gutenberg, and more.
Utimate Kit ( Styler ) for WPForms
styler-for-wpforms
Ultimate Kit for WPForms makes the task of designing WPForms an easy one.
Input Mask For Elementor Form Fields
mask-form-elementor
Apply input masks in Elementor form widget fields - phone, date, time, credit card, CPF, CNPJ, CEP & more for valid and error-free entries.
Simple Coherent Form Developer Profile
5 plugins · 160 total installs
How We Detect Simple Coherent Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-coherent-form/assets/css/scf-front.css/wp-content/plugins/simple-coherent-form/assets/js/scf-front.js/wp-content/plugins/simple-coherent-form/assets/js/datepicker.js/wp-content/plugins/simple-coherent-form/assets/js/scf-front.js/wp-content/plugins/simple-coherent-form/assets/js/datepicker.jssimple-coherent-form/assets/css/scf-front.css?ver=simple-coherent-form/assets/js/scf-front.js?ver=simple-coherent-form/assets/js/datepicker.js?ver=HTML / DOM Fingerprints
scf-datepickerscf-field-wrapperdata-scf-fielddata-scf-typedata-scf-datepicker-optionsscf_data[simple-coherent-form]