
AMP Contact FORM 7 – AMPCF7 Security & Risk Analysis
wordpress.org/plugins/amp-contact-form-7Enable Contact Form 7 plugin support in AMP.
Is AMP Contact FORM 7 – AMPCF7 Safe to Use in 2026?
Generally Safe
Score 85/100AMP Contact FORM 7 – AMPCF7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "amp-contact-form-7" plugin v1.0.1 exhibits a concerning security posture due to a significant lack of input validation and authorization checks on its entry points. All identified entry points, which consist of two AJAX handlers, are unprotected, meaning any unauthenticated user can trigger them. The taint analysis revealing two flows with unsanitized paths, although not flagged as critical or high severity, directly correlates with these unprotected AJAX handlers and represents a potential risk. The complete absence of output escaping on all identified outputs is also a major weakness, opening the door for Cross-Site Scripting (XSS) vulnerabilities. Despite a clean vulnerability history, this does not negate the immediate risks identified in the code analysis. The plugin's strengths lie in its use of prepared statements for SQL queries, which is a good practice. However, the critical deficiencies in authorization and output sanitization far outweigh this positive aspect, making the plugin a high-risk component without further remediation.
Key Concerns
- AJAX handlers without auth checks
- Output escaping missing
- Taint flows with unsanitized paths
- File operations present
AMP Contact FORM 7 – AMPCF7 Security Vulnerabilities
AMP Contact FORM 7 – AMPCF7 Code Analysis
Output Escaping
Data Flow Analysis
AMP Contact FORM 7 – AMPCF7 Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
AMP Contact FORM 7 – AMPCF7 Maintenance & Trust
Maintenance Signals
Community Trust
AMP Contact FORM 7 – AMPCF7 Alternatives
Active Campaign & Contact Form 7
wpop-accf
Add Contact Form 7 Data to ActiveCampaign Contact lists.
CWW connector Lite – Connect Contact Form 7 & ActiveCampaign
cww-connector-lite
CWW Connector Lite is an addon for contact form 7 which allows you to collect leads from contact form 7 to ActiveCampaign.
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Advanced Contact form 7 DB
advanced-cf7-db
Save all contact form 7 form submitted data to the database, View, Ordering, Change field labels and Import/Export data using CSV.
AMP Contact FORM 7 – AMPCF7 Developer Profile
6 plugins · 621K total installs
How We Detect AMP Contact FORM 7 – AMPCF7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/amp-contact-form-7/css/cf7.cssHTML / DOM Fingerprints
ampcf7-successampcf7-errorscriptComponent/wp-json/ampcf7/submit_form<div submitting><template type="amp-mustache"></template></div><div submit-success>