
WP Contacts Slim Security & Risk Analysis
wordpress.org/plugins/wp-contacts-slimTake complete control of your own leads and contacts right in your WordPress installation, powerful features and easy to use.
Is WP Contacts Slim Safe to Use in 2026?
Generally Safe
Score 100/100WP Contacts Slim has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-contacts-slim" v1.0.0 plugin exhibits significant security concerns primarily due to its large, unprotected attack surface and the presence of dangerous functions. All identified entry points, including AJAX handlers and REST API routes, lack proper authentication or permission checks, making them highly susceptible to unauthorized access and manipulation. The extensive use of the `unserialize` function, a known vector for remote code execution when handling untrusted input, is a critical red flag. Taint analysis further highlights these issues, revealing four high-severity flows where unsanitized data could potentially be exploited. The static analysis also indicates that a substantial portion of SQL queries and output operations are not properly secured, increasing the risk of injection attacks and cross-site scripting (XSS).
Despite the absence of recorded historical vulnerabilities (CVEs), this can be misleading. The current code analysis reveals a strong potential for exploitation due to fundamental security misconfigurations. The plugin demonstrates a clear disregard for basic WordPress security best practices, particularly concerning input validation and authorization. While the presence of nonce checks and capability checks in some areas is a positive sign, their limited application fails to mitigate the overarching risks. The plugin's current state presents a high risk to WordPress installations and should be addressed with immediate remediation.
Key Concerns
- All AJAX handlers lack auth checks
- REST API route lacks permission callback
- 4 high severity taint flows
- Uses unserialize function
- Low percentage of prepared SQL statements
- Low percentage of properly escaped output
- Bundled TinyMCE v1.0
- Bundled Select2
WP Contacts Slim Security Vulnerabilities
WP Contacts Slim Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Contacts Slim Attack Surface
AJAX Handlers 6
REST API Routes 1
WordPress Hooks 46
Scheduled Events 1
Maintenance & Trust
WP Contacts Slim Maintenance & Trust
Maintenance Signals
Community Trust
WP Contacts Slim Alternatives
Funnel
funnel
Streamline Your Marketing: Effortlessly Navigate User Conversion Paths
ScuolaSemplice Contacts
scuolasemplice-contacts
Plugin that allows you to publish contact forms to acquire leads and student data that will be automatically imported into the ScuolaSemplice software
Get Telephone Contacts of Prospective Customers
business-contacts-authentic-verifiable-business-leads
Authentic & verifiable telephone contacts of prospective customers in different sectors, countries & states). We help to fetch verifiable busi …
Easy Leads Free
easy-leads-free
Easy Leads Free - collect leads and contacts from your website to the database. Send mails to your leads from the admin panel after.
Formular af CitizenOne journalsystem
formular-af-citizenone-journalsystem
Embed customizable contact forms from CitizenOne on any WordPress site.
WP Contacts Slim Developer Profile
1 plugin · 10 total installs
How We Detect WP Contacts Slim
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-contacts-slim/assets/css/wcp-admin.css/wp-content/plugins/wp-contacts-slim/assets/css/wcp-front.css/wp-content/plugins/wp-contacts-slim/assets/js/wcp-admin.js/wp-content/plugins/wp-contacts-slim/assets/js/wcp-front.jswp-contacts-slim/assets/css/wcp-admin.css?ver=wp-contacts-slim/assets/css/wcp-front.css?ver=wp-contacts-slim/assets/js/wcp-admin.js?ver=wp-contacts-slim/assets/js/wcp-front.js?ver=HTML / DOM Fingerprints
shwcp-admin-wrapshwcp-main-wrapper<!-- WP Contacts Slim plugin by ScriptHat --><!-- For easier overriding we declared the keys * here as well as our tabs array which is populated * when registering settings+6 moredata-shwcp-dbshwcp_optionsshwcp_vars/wp-json/wpcontacts/v1