
AC CF7 Form Field Repeater Security & Risk Analysis
wordpress.org/plugins/ac-cf7-form-field-repeaterAdds repeatable field groups to Contact Form 7.
Is AC CF7 Form Field Repeater Safe to Use in 2026?
Generally Safe
Score 85/100AC CF7 Form Field Repeater has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ac-cf7-form-field-repeater" plugin v0.0.4 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, file operations, or external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output (89%) indicates good practices in preventing cross-site scripting vulnerabilities. The plugin also demonstrates a minimal attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events that could be exploited.
However, the static analysis did reveal a potential concern: a lack of nonce checks. While the plugin has only one capability check, the absence of nonce validation on potential entry points (even if there are currently none) could become a significant weakness if the attack surface were to expand in future versions or if a vulnerability were introduced. The taint analysis shows zero flows, which is excellent, but this should be viewed in conjunction with the other findings.
The vulnerability history is completely clear, with zero recorded CVEs. This suggests a well-maintained and secure plugin, or at least one that hasn't been a target of significant past exploitation. In conclusion, the plugin is currently very secure with excellent code hygiene. The primary area for improvement, and a minor concern, lies in the potential for adding nonce checks to future entry points to further bolster its security.
Key Concerns
- Missing nonce checks
AC CF7 Form Field Repeater Security Vulnerabilities
AC CF7 Form Field Repeater Release Timeline
AC CF7 Form Field Repeater Code Analysis
Output Escaping
AC CF7 Form Field Repeater Attack Surface
WordPress Hooks 11
Maintenance & Trust
AC CF7 Form Field Repeater Maintenance & Trust
Maintenance Signals
Community Trust
AC CF7 Form Field Repeater Alternatives
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 Modules
contact-form-7-modules
Contact Form 7 - Add useful modules such as hidden fields and "send all fields" to the Contact Form 7 plugin
Repeater Fields for Gravity Forms
repeater-for-gravity-forms
The Repeater Fields for Gravity Forms allow you to create one or more sets of fields that can be repeated.
Repeater Fields for Elementor Forms
repeater-for-elementor
The Repeater Fields for Elementor Forms allow you to create one or more sets of fields that can be repeated.
Repeater Fields for WPForms
repeater-field-for-wpforms
The Repeater Fields for WPForms allow you to create one or more sets of fields that can be repeated.
AC CF7 Form Field Repeater Developer Profile
4 plugins · 540 total installs
How We Detect AC CF7 Form Field Repeater
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ac-cf7-form-field-repeater/assets/js/scripts_admin.js/wp-content/plugins/ac-cf7-form-field-repeater/assets/js/scripts.js/wp-content/plugins/ac-cf7-form-field-repeater/assets/js/scripts_admin.js/wp-content/plugins/ac-cf7-form-field-repeater/assets/js/scripts.jsac-cf7-form-field-repeater/assets/js/scripts_admin.js?ver=ac-cf7-form-field-repeater/assets/js/scripts.js?ver=HTML / DOM Fingerprints
acffr-repeater-add-btnacffr-repeater-del-btn<!-- Test if new 4.6+ functions exists -->data-namedata-type