contactform.php
Find: function sendMessage().
Add your message control.
Add after $clientTokenTTL:
$restricts = ['#','/','$','%','*']; $isValidMessage = true; foreach ($restricts as $restrict) { if (strpos($message, $restrict) !== false){$isValidMessage = false;} }
And update:
elseif (!Validate::isCleanHtml($message))
To:
elseif (!Validate::isCleanHtml($message) || $isValidMessage == false)