
Contact Info Widget Security & Risk Analysis
wordpress.org/plugins/simple-contact-info-widgetThis plugin shows a widget with contact info.
Is Contact Info Widget Safe to Use in 2026?
Use With Caution
Score 63/100Contact Info Widget has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "simple-contact-info-widget" plugin v2.6.2 presents a mixed security posture. While the static analysis shows a zero attack surface with no direct entry points like AJAX handlers, REST API routes, or shortcodes without authentication, and all SQL queries utilize prepared statements, there are significant concerns. The presence of the dangerous `create_function` and a very low percentage of properly escaped output (16%) are major red flags, indicating potential for cross-site scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks further exacerbates these risks, as it implies that even if data is processed, it might not be adequately protected against unauthorized or malicious manipulation.
The plugin's vulnerability history, specifically one known medium-severity CVE related to cross-site scripting, reinforces the concerns raised by the code analysis. The fact that this vulnerability is currently unpatched and the last reported vulnerability was in the future (2025-08-17, likely a typo in the provided data, but it still indicates a recent or ongoing issue) suggests a pattern of security weaknesses that may not be actively addressed. Despite the positive aspects of secure SQL handling and no file operations or external HTTP requests, the identified code signals and historical vulnerabilities point to a plugin that requires careful attention and remediation to mitigate risks to users.
Key Concerns
- Unpatched CVE present
- Low output escaping percentage
- Dangerous function 'create_function' used
- No nonce checks detected
- No capability checks detected
Contact Info Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Contact Info Widget <= 2.6.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Contact Info Widget Code Analysis
Dangerous Functions Found
Output Escaping
Contact Info Widget Attack Surface
WordPress Hooks 7
Maintenance & Trust
Contact Info Widget Maintenance & Trust
Maintenance Signals
Community Trust
Contact Info Widget Alternatives
Contact Information Widget
contact-information-widget
Easily add a Contact Information Widget to your widgetable sidebar. With this plugin you can add a contact information.
Widget Contact Now
widget-contact-now
Add contact information quickly and easily with ready-made labels. Display gorgeous contact information on your website with simple, easy-to-use widge …
Contact Information Widget
simple-contact-information-widget
Contact Information Widget.
SiteOrigin Widgets Bundle
so-widgets-bundle
Essential elements for modern websites. Add buttons, sliders, heroes, maps, images, carousels, features, icons, more. Create dynamic pages easily.
Contact Form 7 Widget
contact-form-7-widget
Use your Contact Form 7 forms and other shortcodes in your sidebars.
Contact Info Widget Developer Profile
4 plugins · 2K total installs
How We Detect Contact Info Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.