
Simple Contacts Manager Security & Risk Analysis
wordpress.org/plugins/simple-contacts-managerA simple contact manager for your personal and business use.
Is Simple Contacts Manager Safe to Use in 2026?
Generally Safe
Score 85/100Simple Contacts Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "simple-contacts-manager" v1.3.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding direct SQL queries and performing all its database interactions using prepared statements, indicating a reduced risk of SQL injection. The plugin also has a very small attack surface with no AJAX handlers or REST API routes, and no cron events, minimizing potential entry points for attackers. There is no recorded vulnerability history, which generally suggests a stable and well-maintained plugin.
However, significant security concerns are present in the code analysis. The presence of the `unserialize` function, especially without accompanying validation or sanitization, is a critical risk. If user-controlled data is passed to `unserialize`, it can lead to Remote Code Execution (RCE) vulnerabilities. Furthermore, the fact that 100% of outputs are not properly escaped is a major concern, opening the door for Cross-Site Scripting (XSS) attacks. The absence of nonce and capability checks on its single shortcode also means that any authenticated user could potentially trigger its functionality without proper authorization checks, leading to unexpected behavior or potential exploitation.
In conclusion, while the plugin has a clean vulnerability history and good practices in SQL handling and attack surface minimization, the critical risk posed by `unserialize` and the widespread lack of output escaping are significant weaknesses that demand immediate attention. These issues outweigh the strengths, making the plugin moderately to highly risky in its current state.
Key Concerns
- Dangerous function 'unserialize' used
- No output escaping
- No nonce checks
- No capability checks
Simple Contacts Manager Security Vulnerabilities
Simple Contacts Manager Release Timeline
Simple Contacts Manager Code Analysis
Dangerous Functions Found
Output Escaping
Simple Contacts Manager Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Simple Contacts Manager Maintenance & Trust
Maintenance Signals
Community Trust
Simple Contacts Manager Alternatives
Contacts BMLT
contacts-bmlt
Contacts BMLT is a plugin that displays helpline and website information about service bodies using the contacts_bmlt shortcode.
Simple Taxonomy WYSIWYG
simple-taxonomy-wysiwyg
A very simple plugin that will convert the taxonomy/category description textarea to a WYSIWYG (TinyMCE) form.
SiteStats Analytics – Google Analytics, Bing Webmaster & Search Console
sitestats-analytics
Drag-and-drop WordPress analytics dashboard that combines data from Google Analytics, Search Console, Bing Webmaster, WordPress, WooCommerce & others.
Gallery Made Easy
gallery-made-easy
Instantly create responsive image galleries within a simple and customizable interface. Just upload, add, organise and publish.
Simple Posts Generator
simple-posts-generator
A straight forward Posts Generator for Developers and Testers.
Simple Contacts Manager Developer Profile
4 plugins · 70 total installs
How We Detect Simple Contacts Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-contacts-manager/css/style.css/wp-content/plugins/simple-contacts-manager/js/script.js/wp-content/plugins/simple-contacts-manager/js/script.jssimple-contacts-manager/style.css?ver=simple-contacts-manager/js/script.js?ver=HTML / DOM Fingerprints
w3b-cm-settings-formw3b-cm-contacts-formw3b-cm-group-settingsw3b-cm-contact-detailsdata-plugin-name="Simple Contacts Manager"data-plugin-version="1.3.1"window.W3B_Contacts_Managervar W3B_Contacts_Manager[cm_contact]