
Widget Contact Now Security & Risk Analysis
wordpress.org/plugins/widget-contact-nowAdd contact information quickly and easily with ready-made labels. Display gorgeous contact information on your website with simple, easy-to-use widge …
Is Widget Contact Now Safe to Use in 2026?
Generally Safe
Score 85/100Widget Contact Now has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the 'widget-contact-now' plugin version 1.0.1 exhibits a strong security posture with several positive indicators. The absence of known CVEs, coupled with a lack of recorded vulnerability types, suggests a history of secure development or a low profile in terms of discovered flaws. The code analysis further supports this, showing no dangerous functions, no raw SQL queries, no file operations, and no external HTTP requests. The clean taint analysis with zero flows and zero unsanitized paths is also a significant strength.
However, there are areas that warrant attention. The complete absence of nonce checks and capability checks across all entry points (even though the attack surface is currently reported as zero) presents a potential future risk if new entry points are introduced or if the reported attack surface is incomplete. While output escaping is generally good at 81%, the remaining 19% of unescaped outputs could still pose a Cross-Site Scripting (XSS) risk if the data being output is user-controlled and not sufficiently sanitized prior to insertion into the output buffer.
In conclusion, the plugin is currently in a relatively secure state. The development team appears to be following good practices by avoiding known dangerous patterns. The main concern lies in the lack of built-in authorization checks (nonces and capabilities) for any potential future entry points, and the minor percentage of unescaped output that could be exploited under specific circumstances. Vigilance regarding output sanitization and the implementation of robust authorization checks for any future additions would further strengthen its security.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Unescaped output (19%)
Widget Contact Now Security Vulnerabilities
Widget Contact Now Code Analysis
Output Escaping
Widget Contact Now Attack Surface
WordPress Hooks 5
Maintenance & Trust
Widget Contact Now Maintenance & Trust
Maintenance Signals
Community Trust
Widget Contact Now Alternatives
Contact Information Widget
contact-information-widget
Easily add a Contact Information Widget to your widgetable sidebar. With this plugin you can add a contact information.
Contact Information Widget
simple-contact-information-widget
Contact Information Widget.
Personal Contact Info Widget
personal-contact-info-widget
Add a custom Widget to display your profile photo, social media links and contact information.
CB Contact Form
cb-contact-form
A very simple contact form plugin for Wordpress
Company Data Manager
company-data-manager
A plugin for managing and displaying essential company information, including contact details and social media links.
Widget Contact Now Developer Profile
3 plugins · 630 total installs
How We Detect Widget Contact Now
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/widget-contact-now/assets/css/widget-contacts.csswidget-contact-now/assets/css/widget-contacts.css?ver=widget-contact-now/js/widget-contacts.js?ver=HTML / DOM Fingerprints
widget-contact-nowwidget-contactSTART Widget Contacts By LongVietWeb.comEND Widget Contacts By LongVietWeb.comclass="contacts"id="widgets-right .widget:has(.contacts)"LV_WIDGET_CONTACT_NOW_VERSIONLV_WIDGET_CONTACT_NOW_DIRLV_WIDGET_CONTACT_NOW_URI