Themeable Contact Form Security & Risk Analysis

wordpress.org/plugins/themeable-contact-form

A simple contact form plugin that allows you to customize the template to match your theme

0 active installs v1.0.0 PHP + WP 4.4+ Updated Nov 29, 2025
bootstrapcontactcontact-formformfoundation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Themeable Contact Form Safe to Use in 2026?

Generally Safe

Score 100/100

Themeable Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "themeable-contact-form" plugin v1.0.0 demonstrates a strong security posture based on the provided static analysis. It exhibits excellent practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and properly escaping the vast majority of its output. The plugin also incorporates critical security measures like nonce and capability checks, and importantly, has no file operations or external HTTP requests, significantly reducing common attack vectors. The absence of any Taint Analysis findings, even with zero flows analyzed, and a clean vulnerability history with no known CVEs further bolster its security profile.

Vulnerabilities
None known

Themeable Contact Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Themeable Contact Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
50 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped54 total outputs
Attack Surface

Themeable Contact Form Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[themeable_contact_form] src\ThemeableContactForm\ContactForm.php:97
WordPress Hooks 5
actioninitincludes\functionality.php:19
actionwp_mail_failedincludes\functionality.php:43
actionadmin_menuincludes\options.php:28
actionadmin_initincludes\options.php:99
actionadmin_noticesthemeable-contact-form.php:24
Maintenance & Trust

Themeable Contact Form Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 29, 2025
PHP min version
Downloads239

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Themeable Contact Form Developer Profile

Peter Hebert

3 plugins · 130 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Themeable Contact Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/themeable-contact-form/assets/js/form.js/wp-content/plugins/themeable-contact-form/assets/css/style.css
Script Paths
/wp-content/plugins/themeable-contact-form/assets/js/form.js
Version Parameters
themeable-contact-form/assets/js/form.js?ver=themeable-contact-form/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
themeable-contact-form
Data Attributes
data-plugin-name="themeable-contact-form"
JS Globals
TCF_ContactForm
Shortcode Output
[themeable_contact_form]
FAQ

Frequently Asked Questions about Themeable Contact Form