AMP for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/amp-for-contact-form-7

You would now be able to empower contact form 7 module support in amp with only a single tick! This will work with the structure developer and a wide …

40 active installs v1.3.2 PHP 5.2.4+ WP 4.0+ Updated Sep 9, 2021
ampamp-for-contact-form-7contact-form-7
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is AMP for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

AMP for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The 'amp-for-contact-form-7' plugin exhibits a strong security posture based on the provided static analysis. The complete absence of detectable entry points like AJAX handlers, REST API routes, shortcodes, and cron events, coupled with zero unprotected points, significantly reduces the potential attack surface. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. The lack of external HTTP requests and the absence of dangerous functions further contribute to a secure foundation.

However, there are some areas for improvement. The complete lack of nonce checks and capability checks across all code sections is a notable concern. While the current data indicates no direct vulnerabilities, these checks are fundamental security mechanisms for preventing unauthorized actions and are often exploited in conjunction with other weaknesses. The plugin's vulnerability history shows no recorded CVEs, which is a positive indicator, suggesting that past versions have been relatively secure or have not been targeted. The absence of common vulnerability types further reinforces this perception.

In conclusion, the 'amp-for-contact-form-7' plugin appears to be a well-coded and secure option from a basic analysis perspective, demonstrating excellent practices in SQL and output handling. The most significant weakness lies in the absence of essential authentication and authorization checks, particularly nonces and capability checks. While this has not led to known vulnerabilities, it represents a potential risk that could be exploited if other less obvious weaknesses were present or introduced in future updates. The plugin's clean history is a strong positive, but the lack of foundational security checks is a point that warrants attention.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Unescaped output (17% of 23)
Vulnerabilities
None known

AMP for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

AMP for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped23 total outputs
Attack Surface

AMP for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionadmin_enqueue_scriptsincludes\Admin\Admin.php:22
actionadmin_menuincludes\Admin\Menu.php:21
actionadmin_initincludes\Admin\PluginRequirement.php:18
filterwpcf7_form_novalidateincludes\FrontEnd\Cf7.php:31
filterwpcf7_form_id_attrincludes\FrontEnd\Cf7.php:32
filterwpcf7_change_attsincludes\FrontEnd\Cf7.php:33
filterwpcf7_form_elementsincludes\FrontEnd\Cf7.php:34
actionwp_enqueue_scriptsincludes\FrontEnd\FrontEnd.php:20
actionwpcf7_initincludes\FrontEnd\modules\checkbox.php:2
actionwpcf7_initincludes\FrontEnd\modules\date.php:3
actionwpcf7_initincludes\FrontEnd\modules\file.php:2
actionwpcf7_initincludes\FrontEnd\modules\number.php:2
actionwpcf7_initincludes\FrontEnd\modules\quiz.php:2
actionwpcf7_initincludes\FrontEnd\modules\select.php:2
actionwpcf7_initincludes\FrontEnd\modules\text.php:2
actionwpcf7_initincludes\FrontEnd\modules\textarea.php:2
Maintenance & Trust

AMP for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedSep 9, 2021
PHP min version5.2.4
Downloads5K

Community Trust

Rating100/100
Number of ratings4
Active installs40
Developer Profile

AMP for Contact Form 7 Developer Profile

eSoftArena Ltd.

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AMP for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/amp-for-contact-form-7/includes/Admin/Assets/js/admin.js/wp-content/plugins/amp-for-contact-form-7/includes/Admin/Assets/css/admin.css/wp-content/plugins/amp-for-contact-form-7/includes/FrontEnd/Assets/css/FrontEnd.css
Script Paths
/wp-content/plugins/amp-for-contact-form-7/includes/Admin/Assets/js/admin.js
Version Parameters
amp-for-contact-form-7/includes/Admin/Assets/js/admin.js?ver=amp-for-contact-form-7/includes/Admin/Assets/css/admin.cssamp-for-contact-form-7/includes/FrontEnd/Assets/css/FrontEnd.css

HTML / DOM Fingerprints

JS Globals
ampcf7Ajaxampcf7urlampcf7homeurl
FAQ

Frequently Asked Questions about AMP for Contact Form 7