
WD3K Ajax Sliding Contact Form Security & Risk Analysis
wordpress.org/plugins/wd3k-ajax-sliding-contact-formAn Ajax powered sliding contact form, based on Contactable (jQuery Plugin) By Philip Beel.
Is WD3K Ajax Sliding Contact Form Safe to Use in 2026?
Generally Safe
Score 85/100WD3K Ajax Sliding Contact Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wd3k-ajax-sliding-contact-form" plugin v1.0 presents a significant security risk due to its unprotected AJAX handlers. While the plugin demonstrates good practices in avoiding dangerous functions, using prepared statements for SQL, and not performing file operations or external HTTP requests, the absence of authentication checks on both AJAX entry points is a major concern. This opens the door for attackers to potentially trigger functionalities intended for authenticated users or to manipulate plugin behavior without authorization. The low percentage of properly escaped output also indicates a risk of Cross-Site Scripting (XSS) vulnerabilities, allowing for the injection of malicious scripts through user-controlled input displayed by the plugin.
The plugin's vulnerability history is clean, with no recorded CVEs. This might suggest a lack of past exploitation or that the plugin has been well-maintained historically. However, the static analysis results highlight critical weaknesses in the current version that could be exploited irrespective of past history. The total lack of nonce checks on AJAX handlers, combined with the unprotected entry points, significantly increases the attack surface. A balanced conclusion would note the absence of dangerous functions and SQL vulnerabilities as positives, but the unprotected AJAX handlers and insufficient output escaping are critical flaws that demand immediate attention to mitigate potential security breaches.
Key Concerns
- AJAX handlers without authentication checks
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
WD3K Ajax Sliding Contact Form Security Vulnerabilities
WD3K Ajax Sliding Contact Form Code Analysis
Output Escaping
WD3K Ajax Sliding Contact Form Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
WD3K Ajax Sliding Contact Form Maintenance & Trust
Maintenance Signals
Community Trust
WD3K Ajax Sliding Contact Form Alternatives
Grunion Ajax
grunion-ajax
Using Grunion Contact Form? Make form submission slick with Grunion Ajax.
Contact Dialog
contact-dialog
Enables display of an AJAX driven contact form when a user clicks on links with a specified class.
Contact AJAX forms
contact-ajax-form
Easily add Contact AJAX forms to any page, post or widget area with an unlimited number of custom fields. Easy to manage and style!
Drag and Drop Multiple File Upload for Contact Form 7
drag-and-drop-multiple-file-upload-contact-form-7
This simple plugin create Drag & Drop or choose Multiple File upload in your Confact Form 7 Forms.
Ajax Archive Calendar
ajax-archive-calendar
Ajax Archive Calendar .
WD3K Ajax Sliding Contact Form Developer Profile
11 plugins · 2K total installs
How We Detect WD3K Ajax Sliding Contact Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wd3k-ajax-sliding-contact-form/contactable/contactable.css/wp-content/plugins/wd3k-ajax-sliding-contact-form/contactable/images/btn-close.png/wp-content/plugins/wd3k-ajax-sliding-contact-form/contactable/images/ajax-loader.gif/wp-content/plugins/wd3k-ajax-sliding-contact-form/contactable/jquery.contactable.js/wp-content/plugins/wd3k-ajax-sliding-contact-form/contactable/jquery.validate.pack.js/wp-content/plugins/wd3k-ajax-sliding-contact-form/contactable/jquery.form.populate.js/wp-content/plugins/wd3k-ajax-sliding-contact-form/my.contactable.jswd3k-ajax-sliding-contact-form/contactable/jquery.contactable.js?ver=3.1wd3k-ajax-sliding-contact-form/contactable/jquery.validate.pack.js?ver=3.1wd3k-ajax-sliding-contact-form/contactable/jquery.form.populate.js?ver=3.1wd3k-ajax-sliding-contact-form/my.contactable.js?ver=3.1HTML / DOM Fingerprints
CNContact/wp-json/wd3k-ajax-sliding-contact-form/v1/contact<div id="mycontactform"> </div>