
YM Contact Display Security & Risk Analysis
wordpress.org/plugins/ym-contact-displayThis plugin can be used to show your information such as Company Name, Address, Phone, Fax, Email.
Is YM Contact Display Safe to Use in 2026?
Generally Safe
Score 85/100YM Contact Display has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ym-contact-display" plugin v1.0 exhibits a generally positive security posture, with no known CVEs and no reported vulnerabilities. The static analysis shows a lack of attack surface through traditional entry points like AJAX handlers, REST API routes, and shortcodes. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are common vectors for exploitation. However, the presence of the `create_function` call is a significant concern as it is deprecated and can lead to security vulnerabilities if used improperly, especially with user-supplied input. While taint analysis shows no immediate issues, the `create_function` function itself represents a potential risk that hasn't been fully mitigated through proper sanitization or avoidance.
The plugin's output escaping is only at 48%, indicating a substantial number of potential cross-site scripting (XSS) vulnerabilities. This weakness, coupled with the `create_function` issue, presents a notable risk. The lack of nonce checks and capability checks on any potential (though currently unexposed) entry points is also a concern, as it leaves any future additions to the attack surface unprotected. The absence of vulnerability history is a positive sign but doesn't negate the risks identified in the code analysis. In conclusion, while the plugin has a clean history and a small attack surface, the identified code quality issues related to `create_function` and insufficient output escaping warrant attention to prevent potential security breaches.
Key Concerns
- Use of create_function
- Insufficient output escaping (48%)
- Missing nonce checks
- Missing capability checks
YM Contact Display Security Vulnerabilities
YM Contact Display Code Analysis
Dangerous Functions Found
Output Escaping
YM Contact Display Attack Surface
WordPress Hooks 1
Maintenance & Trust
YM Contact Display Maintenance & Trust
Maintenance Signals
Community Trust
YM Contact Display Alternatives
Speed Contact Bar
speed-contact-bar
Let your website visitors get in touch with you easily with permanent visible contact information.
Disable Flamingo Addressbook
disable-flamingo-addressbook
With this plugin activated, Flamingo will not add any data to its address book.
Autocomplete Location Field for Contact Form 7
autocomplete-location-field-contact-form-7
Add a Google Address Autocomplete field to Contact Form 7 forms. Powered by Google Places API for real-time address suggestions and accurate data coll …
Address autocomplete Contact Form 7
address-autocomplete-contact-form-7
Contact form 7 address autocomplete feature. We are using google maps api. https://maps.googleapis.com/maps/api
Postcodes4U Address Finder
postcodes4u-address-finder
Requires WooCommerce at least: 2.2.3 Tested WooCommerce up to: 10.5.1 Tested ContactForm7 4.9.2 - 6.1.5 Tested Gravity Forms 2.4.15 - 2.9.
YM Contact Display Developer Profile
2 plugins · 60 total installs
How We Detect YM Contact Display
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
ym-contact-displayaddresspad-bot1pad-bot72<div class="ym-contact-display"><p class="address pad-bot1"><p class="address pad-bot72">