
Advanced Custom Fields Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/acf-contact-form-7Adds a new 'Contact Form 7' field to the popular Advanced Custom Fields plugin.
Is Advanced Custom Fields Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100Advanced Custom Fields Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "acf-contact-form-7" plugin version 1.1.6 presents a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in zero total entry points. Furthermore, the absence of dangerous function usage, raw SQL queries, file operations, external HTTP requests, and the fact that all SQL queries utilize prepared statements are all positive indicators. The plugin also does not appear to bundle any external libraries, which can often be a source of vulnerabilities.
However, a notable concern arises from the output escaping. With 7 total outputs and only 57% properly escaped, there is a significant potential for cross-site scripting (XSS) vulnerabilities. This means that data displayed to users might not be adequately sanitized, allowing for malicious scripts to be injected. The lack of nonce checks and capability checks, while not directly indicated as issues by the analysis (due to the limited attack surface), could become a concern if the attack surface were to expand in future versions or if there are other implicit vulnerabilities not caught by this specific analysis.
Given the complete absence of any recorded vulnerabilities or CVEs, the plugin has a clean track record. This, combined with the strong technical measures like prepared statements and lack of dangerous functions, suggests a generally well-developed plugin. The primary area of weakness is the insufficient output escaping, which requires immediate attention to mitigate XSS risks. Overall, the plugin is technically sound with a good history, but the unescaped output introduces a tangible risk.
Key Concerns
- Insufficient output escaping
Advanced Custom Fields Contact Form 7 Security Vulnerabilities
Advanced Custom Fields Contact Form 7 Code Analysis
Output Escaping
Advanced Custom Fields Contact Form 7 Attack Surface
WordPress Hooks 1
Maintenance & Trust
Advanced Custom Fields Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Custom Fields Contact Form 7 Alternatives
Advanced Custom Fields – Contact Form 7 Field
advanced-custom-fields-contact-form-7-field
Adds a 'Contact Form 7' field type for the Advanced Custom Fields WordPress plugin.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
ACF: Better Search
acf-better-search
This plugin adds to default WordPress search engine the ability to search by content from selected fields of Advanced Custom Fields plugin.
Advanced Custom Fields Contact Form 7 Developer Profile
1 plugin · 800 total installs
How We Detect Advanced Custom Fields Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/acf-contact-form-7/fields/