Storefront Homepage Contact Section Security & Risk Analysis

wordpress.org/plugins/storefront-homepage-contact-section

Add a "Contact" section to the Storefront homepage.

1K active installs v1.0.5 PHP + WP 4.0+ Updated Aug 27, 2020
contactecommerceformstorefrontwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Storefront Homepage Contact Section Safe to Use in 2026?

Generally Safe

Score 85/100

Storefront Homepage Contact Section has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The storefront-homepage-contact-section plugin version 1.0.5 demonstrates a generally good security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs and the consistent use of prepared statements for SQL queries are strong indicators of sound development practices and a commitment to security over time. The plugin also shows no signs of file operations or external HTTP requests, which are common vectors for compromise. However, the analysis does highlight a significant concern: a complete lack of capability checks and nonce checks across all identified entry points (though the attack surface itself is zero). While there are currently no unprotected entry points, this omission means that if any new entry points were introduced or if existing ones were exposed inadvertently, they would lack crucial authorization and integrity protections. The 33% of improperly escaped output, while not critical in isolation given the zero attack surface, represents a potential weakness that could be exploited if the plugin were to evolve to include user-facing output from dynamic data without proper sanitization.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
  • Improperly escaped output detected
Vulnerabilities
None known

Storefront Homepage Contact Section Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Storefront Homepage Contact Section Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped12 total outputs
Attack Surface

Storefront Homepage Contact Section Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actioninitstorefront-homepage-contact-section.php:91
actioninitstorefront-homepage-contact-section.php:93
actionwp_enqueue_scriptsstorefront-homepage-contact-section.php:182
actioncustomize_registerstorefront-homepage-contact-section.php:183
actionadmin_noticesstorefront-homepage-contact-section.php:184
actionhomepagestorefront-homepage-contact-section.php:185
filterbody_classstorefront-homepage-contact-section.php:186
filterstorefront_customizer_morestorefront-homepage-contact-section.php:189
actionadmin_noticesstorefront-homepage-contact-section.php:191
Maintenance & Trust

Storefront Homepage Contact Section Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedAug 27, 2020
PHP min version
Downloads67K

Community Trust

Rating32/100
Number of ratings7
Active installs1K
Developer Profile

Storefront Homepage Contact Section Developer Profile

WooCommerce

36 plugins · 4.7M total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
234 days
View full developer profile
Detection Fingerprints

How We Detect Storefront Homepage Contact Section

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/storefront-homepage-contact-section/assets/css/style.css/wp-content/plugins/storefront-homepage-contact-section/assets/js/script.js
Script Paths
/wp-content/plugins/storefront-homepage-contact-section/assets/js/script.js
Version Parameters
storefront-homepage-contact-section/assets/css/style.css?ver=storefront-homepage-contact-section/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
storefront-homepage-contact-sectionshcs-contact-section-containershcs-contact-section-content
HTML Comments
Storefront Homepage Contact SectionAdds a simple contact section to your Storefront powered site.Main Storefront_Homepage_Contact_Section ClassEnsures only one instance of Storefront_Homepage_Contact_Section is loaded or can be loaded.+18 more
Data Attributes
data-shcs-contact-addressdata-shcs-contact-emaildata-shcs-contact-phonedata-shcs-contact-mapdata-shcs-contact-map-latitudedata-shcs-contact-map-longitude+1 more
JS Globals
StorefrontHomepageContactSection
FAQ

Frequently Asked Questions about Storefront Homepage Contact Section