Add to Google Calendar for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/add-to-google-calendar-contact-form-7

Provides a “Add to Calendar” button when a form is submitted.

100 active installs v1.5 PHP 5.3+ WP 4.1+ Updated May 8, 2019
addtocalendarcontactform7eventbuttonformsgooglecalendar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Add to Google Calendar for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

Add to Google Calendar for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The security posture of the "add-to-google-calendar-contact-form-7" plugin v1.5 appears to be relatively good based on the provided static analysis. The absence of any identified CVEs, critical or high severity taint flows, and dangerous functions suggests a lack of known, exploitable vulnerabilities. The use of prepared statements for SQL queries is a positive sign, indicating that database interactions are handled securely. Furthermore, the plugin has no apparent external HTTP requests or file operations, which reduces the attack surface for certain types of attacks.

However, there are areas that warrant caution. The most significant concern is the 51% proper output escaping rate. This indicates that a considerable portion of the plugin's output is not being properly escaped, leaving it vulnerable to Cross-Site Scripting (XSS) attacks. Additionally, the complete lack of nonce checks and capability checks, combined with zero unprotected entry points, suggests that while there might not be direct entry points for malicious code execution through AJAX or REST, the absence of these standard WordPress security measures for any potential future or unanalyzed functionality could become a weakness. The plugin's vulnerability history being entirely clear is a positive indicator, but it should not be relied upon as a sole measure of security; the code itself must be robust.

In conclusion, while the plugin demonstrates strengths in SQL handling and a clean vulnerability history, the significant percentage of unescaped output represents a tangible risk of XSS. The lack of standard security checks, even with no apparent entry points, is a weakness that could be exploited if new functionalities are introduced or if existing ones are misconfigured. Vigilance regarding output escaping is paramount.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Add to Google Calendar for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Add to Google Calendar for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
23
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

51% escaped47 total outputs
Attack Surface

Add to Google Calendar for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_print_stylesadd-to-calendar-cf7.php:36
actionwpcf7_contact_formadd-to-calendar-cf7.php:65
filterwpcf7_editor_panelsadmin-atc.php:4
actionwpcf7_save_contact_formadmin-atc.php:151
Maintenance & Trust

Add to Google Calendar for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedMay 8, 2019
PHP min version5.3
Downloads5K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Add to Google Calendar for Contact Form 7 Developer Profile

Samuel Silva

6 plugins · 2K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Add to Google Calendar for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/add-to-google-calendar-contact-form-7/admin/css/styles.css/wp-content/plugins/add-to-google-calendar-contact-form-7/frontend/css/styles.css/wp-content/plugins/add-to-google-calendar-contact-form-7/frontend/js/scripts.js
Version Parameters
add-to-google-calendar-contact-form-7/admin/css/styles.css?ver=add-to-google-calendar-contact-form-7/frontend/css/styles.css?ver=add-to-google-calendar-contact-form-7/frontend/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
atc-containeradvise
Data Attributes
id="atc_on"name="atc_on"id="specific_date"name="specific_date"name="event_name"name="event_description"+4 more
JS Globals
atccf7_options_form
FAQ

Frequently Asked Questions about Add to Google Calendar for Contact Form 7