
Advanced Date Time Field For Contact Form 7, Gravity Forms, WPForms Security & Risk Analysis
wordpress.org/plugins/advanced-date-time-fieldThis plugin is a lightweight yet powerful date and time picker designed for popular form builder plugins.
Is Advanced Date Time Field For Contact Form 7, Gravity Forms, WPForms Safe to Use in 2026?
Generally Safe
Score 100/100Advanced Date Time Field For Contact Form 7, Gravity Forms, WPForms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "advanced-date-time-field" plugin v1.0.1 exhibits a generally strong security posture based on the static analysis. The complete absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests are positive indicators. The high percentage of properly escaped output (84%) and the presence of a nonce check are also commendable. The taint analysis revealing no unsanitized paths with critical or high severity further bolsters confidence in the code's security. The plugin's vulnerability history shows zero known CVEs, which is excellent and suggests a history of secure development.
Despite the positive indicators, there is a minor concern regarding the lack of capability checks. While the single AJAX handler has a nonce check, relying solely on nonces without verifying user capabilities can be a weakness, especially if the AJAX handler performs sensitive operations. If an attacker can bypass the nonce mechanism or if the functionality itself is sensitive, the lack of capability checks could lead to unauthorized actions. The absence of REST API routes and shortcodes, while reducing the attack surface, also means these potential entry points haven't been subject to security scrutiny within this plugin.
In conclusion, "advanced-date-time-field" v1.0.1 appears to be a secure plugin with robust coding practices regarding data handling and output escaping. The lack of historical vulnerabilities is a significant strength. The primary area for improvement is the implementation of capability checks for its AJAX endpoint to ensure that only authorized users can interact with its functionality.
Key Concerns
- Missing capability checks on AJAX handler
Advanced Date Time Field For Contact Form 7, Gravity Forms, WPForms Security Vulnerabilities
Advanced Date Time Field For Contact Form 7, Gravity Forms, WPForms Code Analysis
Output Escaping
Data Flow Analysis
Advanced Date Time Field For Contact Form 7, Gravity Forms, WPForms Attack Surface
AJAX Handlers 1
WordPress Hooks 23
Maintenance & Trust
Advanced Date Time Field For Contact Form 7, Gravity Forms, WPForms Maintenance & Trust
Maintenance Signals
Community Trust
Advanced Date Time Field For Contact Form 7, Gravity Forms, WPForms Alternatives
Autopreenchimento de endereço em formulários
cf7-cep-autofill
Preenchimento automático de campos de endereço baseado no CEP informado.
Integration for Zoho CRM and Zoho Bigin – Contact Form 7, WPForms, Elementor, Gravity Forms and More
integrate-any-form-with-zoho-crm
Connect Zoho CRM and Zoho Bigin. Create Leads, Contacts, Accounts, Deals, and Pipelines from any form submission.
Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More
integrate-with-hubspot-crm
Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with HubSpot CRM.
Integration for Mailchimp – Contact Form 7, WPForms, Elementor, Gravity Forms and More
integrate-with-mailchimp
Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with Mailchimp.
Integration for Zoho Campaigns – Contact Form 7, WPForms, Elementor, Gravity Forms and More
integrate-with-zoho-campaigns
Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with Zoho Campaigns.
Advanced Date Time Field For Contact Form 7, Gravity Forms, WPForms Developer Profile
16 plugins · 11K total installs
How We Detect Advanced Date Time Field For Contact Form 7, Gravity Forms, WPForms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/advanced-date-time-field/assets/css/flatpickr.min.css/wp-content/plugins/advanced-date-time-field/assets/css/adtf_style.css/wp-content/plugins/advanced-date-time-field/assets/js/flatpickr.min.js/wp-content/plugins/advanced-date-time-field/assets/js/flatpickr.min.jsadvanced-date-time-field/assets/css/flatpickr.min.css?ver=advanced-date-time-field/assets/css/adtf_style.css?ver=advanced-date-time-field/assets/js/flatpickr.min.js?ver=HTML / DOM Fingerprints
adtf-flatpickr-wrapadtf-admin-wrapdata-adtf-inputadtf_optionsADTF_AJAX_URL/wp-json/adtf/v1/save_integrations