
Add to Google Calendar for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/add-to-google-calendar-contact-form-7Provides a “Add to Calendar” button when a form is submitted.
Is Add to Google Calendar for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100Add to Google Calendar for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "add-to-google-calendar-contact-form-7" plugin v1.5 appears to be relatively good based on the provided static analysis. The absence of any identified CVEs, critical or high severity taint flows, and dangerous functions suggests a lack of known, exploitable vulnerabilities. The use of prepared statements for SQL queries is a positive sign, indicating that database interactions are handled securely. Furthermore, the plugin has no apparent external HTTP requests or file operations, which reduces the attack surface for certain types of attacks.
However, there are areas that warrant caution. The most significant concern is the 51% proper output escaping rate. This indicates that a considerable portion of the plugin's output is not being properly escaped, leaving it vulnerable to Cross-Site Scripting (XSS) attacks. Additionally, the complete lack of nonce checks and capability checks, combined with zero unprotected entry points, suggests that while there might not be direct entry points for malicious code execution through AJAX or REST, the absence of these standard WordPress security measures for any potential future or unanalyzed functionality could become a weakness. The plugin's vulnerability history being entirely clear is a positive indicator, but it should not be relied upon as a sole measure of security; the code itself must be robust.
In conclusion, while the plugin demonstrates strengths in SQL handling and a clean vulnerability history, the significant percentage of unescaped output represents a tangible risk of XSS. The lack of standard security checks, even with no apparent entry points, is a weakness that could be exploited if new functionalities are introduced or if existing ones are misconfigured. Vigilance regarding output escaping is paramount.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
Add to Google Calendar for Contact Form 7 Security Vulnerabilities
Add to Google Calendar for Contact Form 7 Code Analysis
Output Escaping
Add to Google Calendar for Contact Form 7 Attack Surface
WordPress Hooks 4
Maintenance & Trust
Add to Google Calendar for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Add to Google Calendar for Contact Form 7 Alternatives
Contact Form 7 Signature Addon
contact-form-7-signature-addon
Easily add an handwritten signature field to Contact Form 7
CF7 to Airtable
add-on-cf7-for-airtable
Connect Contact Form 7 to Airtable. Automatically sync form entries with Airtable, including custom fields, for seamless data management.
CF7 to Notion
add-on-cf7-for-notion
Connect Contact Form 7 to Notion. Sync form entries with Notion, including custom fields, for efficient data management.
Postcodes4U Address Finder
postcodes4u-address-finder
Requires WooCommerce at least: 2.2.3 Tested WooCommerce up to: 10.5.1 Tested ContactForm7 4.9.2 - 6.1.5 Tested Gravity Forms 2.4.15 - 2.9.
Contact Form 7 Phone Module
contact-form-7-phone-mask-module
Adds phone module to the Contact Form 7 plugin
Add to Google Calendar for Contact Form 7 Developer Profile
6 plugins · 2K total installs
How We Detect Add to Google Calendar for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-to-google-calendar-contact-form-7/admin/css/styles.css/wp-content/plugins/add-to-google-calendar-contact-form-7/frontend/css/styles.css/wp-content/plugins/add-to-google-calendar-contact-form-7/frontend/js/scripts.jsadd-to-google-calendar-contact-form-7/admin/css/styles.css?ver=add-to-google-calendar-contact-form-7/frontend/css/styles.css?ver=add-to-google-calendar-contact-form-7/frontend/js/scripts.js?ver=HTML / DOM Fingerprints
atc-containeradviseid="atc_on"name="atc_on"id="specific_date"name="specific_date"name="event_name"name="event_description"+4 moreatccf7_options_form