
Zontact – Lightweight Floating Contact Button Security & Risk Analysis
wordpress.org/plugins/zontactA simple floating contact button for WordPress fast, accessible, and clutter-free.
Is Zontact – Lightweight Floating Contact Button Safe to Use in 2026?
Generally Safe
Score 100/100Zontact – Lightweight Floating Contact Button has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "zontact" plugin version 1.1.1 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and a complete reliance on prepared statements for all SQL queries are significant strengths. Furthermore, the plugin correctly implements nonce and capability checks for its two AJAX entry points, and the high percentage of properly escaped output suggests a solid effort to prevent cross-site scripting vulnerabilities. The zero recorded CVEs and no history of vulnerabilities further reinforce this positive outlook.
While the static analysis reveals no critical or high-severity vulnerabilities, and the taint analysis found no unsanitized paths, the absence of analysis in these areas (0 flows analyzed) means we cannot definitively rule out such issues. The attack surface is small with only two entry points, both of which are secured with authentication checks, which is excellent. However, a more thorough code review and dynamic analysis would be beneficial to confirm the absence of any latent vulnerabilities, especially in areas not covered by the current analysis scope.
Zontact – Lightweight Floating Contact Button Security Vulnerabilities
Zontact – Lightweight Floating Contact Button Code Analysis
SQL Query Safety
Output Escaping
Zontact – Lightweight Floating Contact Button Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
Zontact – Lightweight Floating Contact Button Maintenance & Trust
Maintenance Signals
Community Trust
Zontact – Lightweight Floating Contact Button Alternatives
Popup addon for Ninja Forms
popup-addon-for-ninja-forms
Popup/Modal addon for Ninja Forms. Create beautiful popups using Ninja Forms for newsletters, login, registration forms.
Lightweight Contact Form
lightweight-contact-form
The most lightweight Contact Form plugin for WordPress. No CSS files, no overhead, no SPAM. The goal is fastest page speed.
Ajax Contact Form
fws-ajax-contact-form
An easy to use contact form plugin with multiple inbuilt features to prevent contact form spam.
Result Popups for CF7
result-popups-for-cf7
Modernize your Contact Form 7 messages with clean, customizable SweetAlert2 popups. No config needed. Just activate and enjoy.
Emberly Popups
emberly-popups
Lightweight, accessible popups for WordPress—made by developers, for developers.
Zontact – Lightweight Floating Contact Button Developer Profile
1 plugin · 0 total installs
How We Detect Zontact – Lightweight Floating Contact Button
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zontact/assets/css/zontact.css/wp-content/plugins/zontact/assets/js/zontact.js/wp-content/plugins/zontact/assets/js/zontact.jszontact/assets/css/zontact.css?ver=zontact/assets/js/zontact.js?ver=HTML / DOM Fingerprints
zontact-rootzontact-leftzontact-rightzontact-buttonzontact-button-size-zontact-button-mode-zontact-button-iconzontact-button-label+15 moredata-accentdata-button-bgdata-button-textdata-button-radiuszontact/wp-json/zontact/v1/submit