Campo RUT para CF7 Security & Risk Analysis

wordpress.org/plugins/add-campo-rut-cf7

Agrega un campo de tipo RUT (Chileno) a Contact Form 7. Este plugin depende de Contact Form 7.

600 active installs v1.4 PHP 5.4+ WP 4.1+ Updated Apr 5, 2022
chilechilenocontact-form-7runrut
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Campo RUT para CF7 Safe to Use in 2026?

Generally Safe

Score 85/100

Campo RUT para CF7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The static analysis of the "add-campo-rut-cf7" v1.4 plugin indicates a generally good security posture. There are no identified dangerous functions, all SQL queries are properly prepared, and all output is correctly escaped. Furthermore, the plugin does not appear to perform file operations or external HTTP requests, and it has no identified CVEs in its history. This suggests that the developers have followed several key security best practices.

However, the analysis reveals a complete absence of nonce checks and capability checks. While the plugin has a reported zero attack surface from AJAX handlers, REST API routes, shortcodes, and cron events, this absence of security mechanisms is concerning. If any of these entry points were to be introduced in future versions without proper authentication and authorization checks, it could lead to significant vulnerabilities. The lack of any taint analysis results could be due to the limited scope of the analysis or the inherent design of the plugin, but it doesn't provide assurance against potential data manipulation issues.

In conclusion, "add-campo-rut-cf7" v1.4 appears to be a secure plugin based on the current analysis, with no known vulnerabilities or obvious code-level risks in its present form. The strength lies in its clean code regarding dangerous functions, SQL, and output escaping. The primary weakness is the complete lack of nonce and capability checks, which, while not currently exploitable due to the limited attack surface, represents a potential future risk if the plugin evolves.

Key Concerns

  • No nonce checks present
  • No capability checks present
Vulnerabilities
None known

Campo RUT para CF7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Campo RUT para CF7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Campo RUT para CF7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwpcf7_initcf7rut.php:14
actionadmin_initcf7rut.php:17
filterwpcf7_messagescf7rut.php:29
filterwpcf7_validate_rutcf7rut.php:30
filterwpcf7_validate_rut*cf7rut.php:31
actionwp_enqueue_scriptscf7rut.php:269
Maintenance & Trust

Campo RUT para CF7 Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.0
Last updatedApr 5, 2022
PHP min version5.4
Downloads5K

Community Trust

Rating80/100
Number of ratings4
Active installs600
Developer Profile

Campo RUT para CF7 Developer Profile

delfo084

1 plugin · 600 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Campo RUT para CF7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-campo-rut-cf7/js/rut.js
Script Paths
/wp-content/plugins/add-campo-rut-cf7/js/rut.js
Version Parameters
add-campo-rut-cf7/js/rut.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpcf7-validates-as-rutwpcf7-rut-onformatwpcf7-rut-onlynumbers
Data Attributes
data-wpcf7-validates-as-rut
Shortcode Output
<span class="wpcf7-form-control-wrap <input type="text" name=" wpcf7-validates-as-rutwpcf7-rut-onformat
FAQ

Frequently Asked Questions about Campo RUT para CF7