
Text Message Contact Form Security & Risk Analysis
wordpress.org/plugins/text-message-contact-formThis is a fully customizable contact form for your website that will send you a text message and e-mail when the form is submitted.
Is Text Message Contact Form Safe to Use in 2026?
Generally Safe
Score 85/100Text Message Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'text-message-contact-form' plugin version 91 exhibits a mixed security posture. While it has a small attack surface and no known vulnerabilities in its history, the static analysis reveals significant concerns, particularly in its output escaping and taint analysis. The extremely low percentage of properly escaped outputs (4%) suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly without proper sanitization. Furthermore, all seven analyzed taint flows contain unsanitized paths, indicating potential risks related to how user input is processed, although these did not escalate to critical or high severity in the analysis. The lack of nonce checks and capability checks on the identified entry point (shortcode) is also a concern, as it could be exploited if the shortcode's functionality involves sensitive operations. Despite the absence of historical CVEs, the current code analysis points to a need for immediate remediation to address the identified output escaping and data sanitization issues.
Key Concerns
- Low percentage of properly escaped outputs
- All taint flows have unsanitized paths
- No nonce checks on entry points
- No capability checks on entry points
Text Message Contact Form Security Vulnerabilities
Text Message Contact Form Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Text Message Contact Form Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Text Message Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
Text Message Contact Form Alternatives
Text Message Contact Form
text-message-contact-form-biztext
Receive a Text or email, from your website through the Text Message Contact Form by Biz Text. SMS notification of email received, no third-party apps …
Contact Form 7
contact-form-7
Just another contact form plugin. Simple but flexible.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Text Message Contact Form Developer Profile
2 plugins · 20 total installs
How We Detect Text Message Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/text-message-contact-form/_include/fbtc-styles.phptext-message-contact-form/style.css?ver=HTML / DOM Fingerprints
redTextnavRednavb1gEmptyread-page-selectedform_textfieldsmallGsmallRed+1 more<!-- ............................FORM START -->id="fbtc_register_dashboard"class="fbtc-menu"id="fbtc_admin"id="var_name"name="var_name"type="hidden"+6 more[text-message-contact-form]