Affiliates Contact Form 7 Integration Security & Risk Analysis

wordpress.org/plugins/affiliates-contact-form-7

Affiliates plugin integration for Contact Form 7. Collect form data & track submissions. Lead tracking, sales, support ...

200 active installs v5.4.0 PHP 7.4+ WP 6.5+ Updated Dec 17, 2025
affiliateaffiliate-marketingaffiliatescontact-form-7referral
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Affiliates Contact Form 7 Integration Safe to Use in 2026?

Generally Safe

Score 100/100

Affiliates Contact Form 7 Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'affiliates-contact-form-7' plugin version 5.4.0 exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries without prepared statements, file operations, or external HTTP requests is commendable. Furthermore, the presence of nonce and capability checks, along with a complete lack of taint flows, suggests a well-developed and secure codebase with minimal opportunities for common vulnerabilities. The plugin also has a clean vulnerability history with no recorded CVEs, indicating a consistent commitment to security by its developers.

However, the static analysis does highlight a potential area for improvement: output escaping. With 84 total outputs and 67% properly escaped, there's a risk of XSS vulnerabilities in the remaining 33% of outputs. While the attack surface appears minimal with no identified entry points that are unprotected, any unescaped output, especially if it handles user-supplied data, could still pose a security risk.

In conclusion, 'affiliates-contact-form-7' v5.4.0 appears to be a secure plugin due to its robust code practices and lack of historical vulnerabilities. The primary concern lies with the incomplete output escaping, which, although not immediately evidenced as exploitable due to the limited attack surface, warrants attention to ensure comprehensive security. The plugin's strengths in avoiding dangerous functions and secure data handling significantly outweigh this single identified weakness.

Key Concerns

  • Output escaping is not 100% comprehensive
Vulnerabilities
None known

Affiliates Contact Form 7 Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Affiliates Contact Form 7 Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
56 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped84 total outputs
Attack Surface

Affiliates Contact Form 7 Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionaffiliates_admin_menuincludes\class-affiliates-cf7-admin.php:38
filteraffiliates_footerincludes\class-affiliates-cf7-admin.php:39
actionwpcf7_before_send_mailincludes\class-affiliates-cf7-handler-legacy.php:37
filterwpcf7_form_hidden_fieldsincludes\class-affiliates-cf7-handler-legacy.php:68
actionwpcf7_before_send_mailincludes\class-affiliates-cf7-handler.php:37
filterwpcf7_form_hidden_fieldsincludes\class-affiliates-cf7-handler.php:68
actioninitincludes\class-affiliates-cf7.php:180
actionadmin_noticesincludes\class-affiliates-cf7.php:208
Maintenance & Trust

Affiliates Contact Form 7 Integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 17, 2025
PHP min version7.4
Downloads28K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

Affiliates Contact Form 7 Integration Developer Profile

itthinx

27 plugins · 23K total installs

98
trust score
Avg Security Score
97/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect Affiliates Contact Form 7 Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/affiliates-contact-form-7/includes/js/affiliates-contact-form-7.js/wp-content/plugins/affiliates-contact-form-7/includes/css/affiliates-contact-form-7.css
Script Paths
/wp-content/plugins/affiliates-contact-form-7/includes/js/affiliates-contact-form-7.js
Version Parameters
affiliates-contact-form-7/includes/js/affiliates-contact-form-7.js?ver=affiliates-contact-form-7/includes/css/affiliates-contact-form-7.css?ver=

HTML / DOM Fingerprints

CSS Classes
affiliates-contact-form-7-wrapper
HTML Comments
<!-- affiliates-contact-form-7 -->
Data Attributes
data-affcf7-id
JS Globals
affiliates_cf7_params
Shortcode Output
[affiliates_cf7_form]
FAQ

Frequently Asked Questions about Affiliates Contact Form 7 Integration