Contact Information Widget Security & Risk Analysis

wordpress.org/plugins/simple-contact-information-widget

Contact Information Widget.

500 active installs v1.0.3 PHP 5.2+ WP 3.5.0+ Updated Apr 5, 2022
contactcontact-informationcontact-information-widgetwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Information Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Information Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin "simple-contact-information-widget" version 1.0.3 exhibits a mixed security posture. On the positive side, static analysis reveals a complete absence of known vulnerabilities (CVEs), dangerous functions, raw SQL queries, file operations, external HTTP requests, and bundled libraries. The attack surface is also zero, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. This suggests a well-contained and potentially secure plugin.

However, a significant concern arises from the output escaping. Only 33% of the total outputs are properly escaped, indicating a high probability of Cross-Site Scripting (XSS) vulnerabilities. While no direct taint flows with unsanitized paths were detected in the static analysis, the lack of robust output escaping is a critical weakness that could be exploited if any user-supplied data is ever rendered on the frontend without proper sanitization. The absence of nonce and capability checks, while not directly flagged as a risk due to the zero attack surface, would become a serious issue if any entry points were introduced in future versions.

In conclusion, the plugin's current state, with no known vulnerabilities and a clean attack surface, is promising. The primary weakness lies in its insufficient output escaping, which presents a substantial XSS risk. Addressing this in future updates is paramount to maintaining a strong security posture. Developers should prioritize implementing proper escaping mechanisms for all frontend output.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Contact Information Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Information Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
49
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped73 total outputs
Attack Surface

Contact Information Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedincludes\contact-information.php:145
actionadmin_enqueue_scriptsincludes\contact-information.php:161
actionadmin_enqueue_scriptsincludes\contact-information.php:163
actionwp_enqueue_scriptsincludes\contact-information.php:179
actionwp_enqueue_scriptsincludes\contact-information.php:181
actionwp_enqueue_scriptsincludes\contact-information.php:183
actionwidgets_initincludes\contact-information.php:185
Maintenance & Trust

Contact Information Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedApr 5, 2022
PHP min version5.2
Downloads6K

Community Trust

Rating94/100
Number of ratings3
Active installs500
Developer Profile

Contact Information Widget Developer Profile

jaydeepchauhan

1 plugin · 500 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Information Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-contact-information-widget/admin/css/contact-information-admin.css/wp-content/plugins/simple-contact-information-widget/admin/js/contact-information-admin.js
Script Paths
/wp-content/plugins/simple-contact-information-widget/admin/js/contact-information-admin.js
Version Parameters
contact-information-admin.css?ver=contact-information-admin.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- An instance of this class should be passed to the run() function defined in Contact_Information_Loader as all of the hooks are defined in that particular class. The Contact_Information_Loader will then create the relationship between the defined hooks and the functions defined in this class. --><!-- An instance of this class should be passed to the run() function defined in Contact_Information_Loader as all of the hooks are defined in that particular class. The Contact_Information_Loader will then create the relationship between the defined hooks and the functions defined in this class. -->
FAQ

Frequently Asked Questions about Contact Information Widget