
Zu Contact Security & Risk Analysis
wordpress.org/plugins/zu-contactSimple but smart and modern Ajax contact form. With Form Blocks and Gutenberg based settings page.
Is Zu Contact Safe to Use in 2026?
Generally Safe
Score 85/100Zu Contact has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "zu-contact" v1.1.5 demonstrates a generally good security posture, with no known vulnerabilities in its history and a solid implementation of security best practices in its static analysis. The absence of known CVEs and the plugin's consistent adherence to prepared statements for SQL queries, alongside a high percentage of properly escaped output, are significant strengths. The limited attack surface, consisting of only two shortcodes and no AJAX or REST API endpoints without authentication, further reduces the potential for direct exploitation.
However, the static analysis does reveal a couple of areas that warrant attention. Specifically, the taint analysis indicates two flows with unsanitized paths, although these are not classified as critical or high severity. This suggests a potential, albeit low-level, risk of improper handling of user-supplied data that could lead to unexpected behavior or information disclosure in specific scenarios. The presence of file operations without further context on their sanitization is also a minor concern.
Overall, "zu-contact" v1.1.5 is a relatively secure plugin. Its strengths lie in its clean vulnerability history and robust implementation of core security measures like prepared statements and output escaping. The identified taint flows, while not critical, are the primary area for improvement to further harden the plugin's security. The lack of any previously recorded vulnerabilities is a positive indicator of the developers' diligence.
Key Concerns
- Flows with unsanitized paths
- File operations without clear sanitization context
Zu Contact Security Vulnerabilities
Zu Contact Release Timeline
Zu Contact Code Analysis
Output Escaping
Data Flow Analysis
Zu Contact Attack Surface
Shortcodes 2
WordPress Hooks 33
Maintenance & Trust
Zu Contact Maintenance & Trust
Maintenance Signals
Community Trust
Zu Contact Alternatives
Contact Form X
contact-form-x
Displays a user-friendly contact form that your visitors will love. Lightweight, fast, secure, and accessible (ADA/WCAG compliant).
woo-shortcode-popup
woo-shortcode-popup
Creates a popup button on woocommerce shop page
More Mails for CF7
more-mails-for-cf7
Extends the ubiquitous Contact Form 7 plugin to allow three or more messages.
Contact Form 7 Countries
cf7-countries
Country drop-down menu for Contact Form 7.
Forms
forms-by-made-it
Build easy and flexible forms with Forms.
Zu Contact Developer Profile
2 plugins · 0 total installs
How We Detect Zu Contact
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zu-contact/dist/js//wp-content/plugins/zu-contact/dist/css//wp-content/plugins/zu-contact/dist/js/zu-contact.min.js/wp-content/plugins/zu-contact/dist/js/zukit.jszu-contact.min.js?ver=zukit.js?ver=HTML / DOM Fingerprints
zucontact_jsdata