
CF7 to Notion Security & Risk Analysis
wordpress.org/plugins/add-on-cf7-for-notionConnect Contact Form 7 to Notion. Sync form entries with Notion, including custom fields, for efficient data management.
Is CF7 to Notion Safe to Use in 2026?
Generally Safe
Score 100/100CF7 to Notion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'add-on-cf7-for-notion' v1.6.0 presents a generally strong security posture with several good practices observed. The absence of known CVEs and a clean vulnerability history are significant positives, suggesting a mature and well-maintained codebase. The static analysis also reveals a robust approach to SQL queries, with 100% using prepared statements, and a very high percentage (98%) of output being properly escaped. The presence of nonce checks further indicates an awareness of common web security threats.
However, there are some areas that warrant attention. The taint analysis identified one flow with unsanitized paths, which, while not flagged as critical or high severity, still represents a potential entry point for vulnerabilities if it involves user-supplied input that is not adequately validated or sanitized. Furthermore, the lack of capability checks on any of the identified entry points is a notable concern. While the attack surface appears minimal (0 AJAX, 0 REST API, etc.), any future expansion or an oversight in code development could expose sensitive operations without proper authorization checks. The file operations and external HTTP requests, while not directly flagged as problematic in the analysis, are always points of scrutiny in security reviews as they can be vectors for more complex attacks.
Overall, the plugin is in a good state, with a low apparent risk. The strengths lie in its clean history and sound handling of common web vulnerabilities like SQL injection and output escaping. The primary weakness is the single identified unsanitized path and the complete absence of capability checks, which, though currently mitigating a low risk due to the limited attack surface, could become more significant if the plugin's functionality grows or is integrated in different contexts.
Key Concerns
- Unsanitized path in taint flow
- No capability checks on entry points
CF7 to Notion Security Vulnerabilities
CF7 to Notion Code Analysis
Output Escaping
Data Flow Analysis
CF7 to Notion Attack Surface
WordPress Hooks 35
Maintenance & Trust
CF7 to Notion Maintenance & Trust
Maintenance Signals
Community Trust
CF7 to Notion Alternatives
CF7 to Airtable
add-on-cf7-for-airtable
Connect Contact Form 7 to Airtable. Automatically sync form entries with Airtable, including custom fields, for seamless data management.
WP Sync for Notion – Notion to WordPress
wp-sync-for-notion
Connect Notion and send data to WordPress with the WP Sync for Notion plugin!
Contact Form 7 Signature Addon
contact-form-7-signature-addon
Easily add an handwritten signature field to Contact Form 7
Address Autocomplete via Google for Gravity Forms
gf-google-address-autocomplete
A simple and nice plugin to get auto suggestion from google place api in gravity form address field.
Quform Zapier
quform-zapier
Easily integrate Zapier with Quform forms.
CF7 to Notion Developer Profile
6 plugins · 4K total installs
How We Detect CF7 to Notion
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-on-cf7-for-notion/assets/style/style.cssHTML / DOM Fingerprints
name="wpc-wpcf7-notion[enable_database]"name="wpc-wpcf7-notion[database_selected]"name="wpc-wpcf7-notion[mapping]"data-field-iddata-column-id