
Zedna Contact form Security & Risk Analysis
wordpress.org/plugins/zedna-contact-formContact from with attachments and reCaptcha in shortcode.
Is Zedna Contact form Safe to Use in 2026?
Generally Safe
Score 85/100Zedna Contact form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zedna-contact-form plugin, version 1.2.2, exhibits a generally good security posture with several strengths. The absence of known vulnerabilities (CVEs) and the low number of flows analyzed in taint analysis suggest a mature and relatively secure codebase. Crucially, all SQL queries are properly prepared, and there are no critical or high-severity taint flows detected, indicating a low risk of SQL injection or other common data manipulation attacks. The presence of a nonce check and the use of prepared statements are positive security practices.
However, there are areas of concern that slightly detract from an otherwise strong profile. The most significant weakness is the lack of capability checks for its single shortcode, which represents an unprotected entry point into the plugin's functionality. While the attack surface is small (only one shortcode), the absence of authorization checks means any logged-in user could potentially interact with it. Additionally, only 67% of output is properly escaped, suggesting a moderate risk of Cross-Site Scripting (XSS) vulnerabilities if sensitive data is displayed to users without sufficient sanitization. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful review in conjunction with the output escaping.
In conclusion, zedna-contact-form version 1.2.2 is likely safe for most deployments due to its clean vulnerability history and secure handling of database interactions. The primary risks stem from the unprotected shortcode and the moderate rate of unescaped output. Addressing these two areas would significantly bolster the plugin's security, bringing it closer to an excellent security posture. The plugin benefits from a small attack surface and good internal coding practices regarding database queries.
Key Concerns
- Shortcode without capability checks
- Moderate output escaping (67% proper)
Zedna Contact form Security Vulnerabilities
Zedna Contact form Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Zedna Contact form Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Zedna Contact form Maintenance & Trust
Maintenance Signals
Community Trust
Zedna Contact form Alternatives
Contact Form by tech-c.net
contact-form-by-tech-c-net
Plugin that shows a contact form by shortcode.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Contact Form 7 Captcha
contact-form-7-simple-recaptcha
Protect your Contact Form 7 forms with Google reCAPTCHA V2, Google reCAPTCHA V3, hCAPTCHA, or Cloudflare Turnstile.
Invisible reCaptcha for WordPress
invisible-recaptcha
Invisible reCaptcha for WordPress plugin helps you to protect your sites against bad spam bots using the new Invisible reCaptcha by Google.
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Zedna Contact form Developer Profile
15 plugins · 570 total installs
How We Detect Zedna Contact form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zedna-contact-form/assets/css/zedna-contact-form.css/wp-content/plugins/zedna-contact-form/assets/js/zedna-contact-form.js/wp-content/plugins/zedna-contact-form/assets/js/zedna-contact-form.jszedna-contact-form/assets/css/zedna-contact-form.css?ver=zedna-contact-form/assets/js/zedna-contact-form.js?ver=HTML / DOM Fingerprints
zedna-contact-form-wrapperzedna-contact-form-inputzedna-contact-form-textareazedna-contact-form-submit<!-- Zedna Contact Form Shortcode--><!-- End Zedna Contact Form Shortcode -->data-plugin-name="zedna-contact-form"data-plugin-version="1.2.2"window.zednaContactFormConfig<form class="zedna-contact-form" method="post"><input type="hidden" name="zedna_contact_form_nonce" value="