
Text Message Contact Form Security & Risk Analysis
wordpress.org/plugins/text-message-contact-form-biztextReceive a Text or email, from your website through the Text Message Contact Form by Biz Text. SMS notification of email received, no third-party apps …
Is Text Message Contact Form Safe to Use in 2026?
Generally Safe
Score 92/100Text Message Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "text-message-contact-form-biztext" plugin v2.0 shows a mixed bag of good practices and concerning omissions. On the positive side, the plugin demonstrates a strong commitment to secure coding by avoiding dangerous functions, performing all SQL queries using prepared statements, and conducting file operations and external HTTP requests, which are all excellent security indicators. It also includes nonce checks, suggesting an awareness of common WordPress vulnerabilities.
However, significant risks are present due to the presence of two AJAX handlers that lack authentication checks. This creates an easily exploitable attack surface, as any unauthenticated user could potentially trigger these handlers. While the taint analysis didn't reveal critical or high severity flows, the single flow with an unsanitized path is a point of concern and warrants further investigation, as it could lead to unintended behavior or security vulnerabilities if it involves user-supplied input.
The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This could indicate a well-maintained codebase or simply a lack of public disclosure of past issues. While a clean history is positive, it should not be a substitute for robust security practices. The limited number of output escaping occurrences (16% properly escaped) is a weakness, potentially leaving the plugin vulnerable to cross-site scripting (XSS) attacks if user-supplied data is displayed without proper sanitization.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Low percentage of properly escaped output
Text Message Contact Form Security Vulnerabilities
Text Message Contact Form Code Analysis
Output Escaping
Data Flow Analysis
Text Message Contact Form Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Text Message Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
Text Message Contact Form Alternatives
Never Loose Contact Form
never-loose-contact-form
Spam proof contact form that emails you the message and saves it in database.
Text Message Contact Form
text-message-contact-form
This is a fully customizable contact form for your website that will send you a text message and e-mail when the form is submitted.
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
Newsletters, Email Marketing, SMS and Popups by Omnisend
omnisend
Newsletters, Email Marketing, Email Automation, Forms, Pop Up, SMS by Omnisend
Email Marketing for WooCommerce by Omnisend
omnisend-connect
Email Marketing, Newsletter, Email Automation, Forms, Pop Up, SMS, Abandoned Cart made easy for WordPress & WooCommerce by Omnisend
Text Message Contact Form Developer Profile
4 plugins · 220 total installs
How We Detect Text Message Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/text-message-contact-form-biztext/wpbiztext-cform.css/wp-content/plugins/text-message-contact-form-biztext/js/biztext_cform_script.js/wp-content/plugins/text-message-contact-form-biztext/wpbiztext-cform-front.css/wp-content/plugins/text-message-contact-form-biztext/js/biztext_cform_script_front.js/wp-content/plugins/text-message-contact-form-biztext/js/biztext_cform_script.js/wp-content/plugins/text-message-contact-form-biztext/js/biztext_cform_script_front.jstext-message-contact-form-biztext/wpbiztext-cform.css?ver=text-message-contact-form-biztext/js/biztext_cform_script.js?ver=text-message-contact-form-biztext/wpbiztext-cform-front.css?ver=text-message-contact-form-biztext/js/biztext_cform_script_front.js?ver=HTML / DOM Fingerprints
<!-- implementation note: checks to see if text message plugin is active; --><!-- users can change plugin names so its better to check if the text message plugin functions have been loaded --><!-- loading and storing cform data --><!-- this saves and loads values from settings fields in database -->+4 morebiztext_cform_options