
autofill-CF7-BB Security & Risk Analysis
wordpress.org/plugins/autofill-cf7-bbAdd shortcode for fields autofill of Contact Form 7 plugin by URL get variable, by Id or by value, or add new value(s).
Is autofill-CF7-BB Safe to Use in 2026?
Generally Safe
Score 85/100autofill-CF7-BB has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The autofill-cf7-bb plugin version 1.0.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for its single SQL query and does not make external HTTP requests. The attack surface is also limited to a single shortcode, with no identified unprotected entry points. However, significant concerns arise from the complete lack of output escaping and the absence of any capability checks or nonce verification. This means that any data processed by the plugin could potentially be outputted to the browser in an unescaped format, opening it up to Cross-Site Scripting (XSS) vulnerabilities. The absence of capability checks for its shortcode is also a worrying sign, as it implies that any authenticated user, regardless of their role, could potentially trigger its functionality, which could be leveraged in conjunction with other vulnerabilities.
The vulnerability history is currently clean, with no known CVEs. This is a positive indicator, suggesting the plugin has not had publicly disclosed security flaws in the past. However, the lack of security features such as output escaping and capability checks means that the potential for new vulnerabilities to be introduced or remain undiscovered is high. In conclusion, while the plugin has a clean history and limits its attack surface and SQL usage, the critical deficiency in output escaping and the complete absence of authorization checks present substantial security risks that require immediate attention.
Key Concerns
- 0% properly escaped output
- 0 capability checks
- 0 nonce checks
autofill-CF7-BB Security Vulnerabilities
autofill-CF7-BB Code Analysis
SQL Query Safety
Output Escaping
autofill-CF7-BB Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
autofill-CF7-BB Maintenance & Trust
Maintenance Signals
Community Trust
autofill-CF7-BB Alternatives
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Contact Form 7 – Dynamic Text Extension
contact-form-7-dynamic-text-extension
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
Export All URLs
export-all-urls
This plugin enables you to extract information such as Title, URL, Categories, Tags, Author, as well as Published and Modified dates for built-in post …
Void Contact Form 7 Widget For Elementor Page Builder
cf7-widget-elementor
This WordPress Plugin Adds Contact Form 7 widget element to Elementor page builder for easy drag & drop the created contact forms with CF7 (contac …
WPML Widgets
wpml-widgets
WPML Widgets is a simple to use extension to add a language selector dropdown to your widgets.
autofill-CF7-BB Developer Profile
2 plugins · 20 total installs
How We Detect autofill-CF7-BB
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/autofill-cf7-bb/script/AFCFBB_js.js/wp-content/plugins/autofill-cf7-bb/script/AFCFBB_js.jsHTML / DOM Fingerprints
AFCFBB_TEXT_DOMAIN[AFCF_BB]