
BCodeCraft Submissions for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/bcodecraft-submissions-cf7Secure storage and management of Contact Form 7 submissions with advanced security features. Never lose a lead again!
Is BCodeCraft Submissions for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100BCodeCraft Submissions for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The bcodecraft-submissions-cf7 plugin version 1.0.0 exhibits a generally good security posture with a high percentage of properly escaped outputs and the extensive use of prepared statements for SQL queries. The plugin also demonstrates a solid implementation of security checks, with a significant number of capability checks and nonce checks. Furthermore, its clean vulnerability history with no recorded CVEs is a positive indicator of its security development practices.
However, the plugin does present some areas of concern that warrant attention. The presence of 12 AJAX handlers, with a notable 4 of them lacking authentication checks, exposes a significant attack surface to potential unauthorized access and manipulation. While the taint analysis did not reveal critical or high severity vulnerabilities, the existence of 3 flows with unsanitized paths is a potential risk that could lead to unexpected behavior or security issues if exploited. The file operations and external HTTP requests are relatively low, which is a positive aspect.
Key Concerns
- AJAX handlers without authentication checks
- Flows with unsanitized paths found
BCodeCraft Submissions for Contact Form 7 Security Vulnerabilities
BCodeCraft Submissions for Contact Form 7 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
BCodeCraft Submissions for Contact Form 7 Attack Surface
AJAX Handlers 12
WordPress Hooks 39
Scheduled Events 3
Maintenance & Trust
BCodeCraft Submissions for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
BCodeCraft Submissions for Contact Form 7 Alternatives
Contact Form Entries Database
contact-form-entries-database
Capture and manage contact form submissions from Contact Form 7, WPForms, and Ninja Forms � store entries in your WordPress database and view them in …
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
FormsDB – Save Elementor Forms to Google Sheets & Post Type
sb-elementor-contact-form-db
Connect Elementor forms with Google Sheets to sync form entries, or save form submissions in any post type using Elementor Pro or Hello Plus forms.
Database for CF7
database-for-cf7
Save CF7 submitted form informations into your WordPress database.
BCodeCraft Submissions for Contact Form 7 Developer Profile
5 plugins · 40 total installs
How We Detect BCodeCraft Submissions for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bcodecraft-submissions-cf7/assets/css/bccs-admin-styles.css/wp-content/plugins/bcodecraft-submissions-cf7/assets/js/bccs-admin-scripts.js/wp-content/plugins/bcodecraft-submissions-cf7/assets/js/bccs-frontend-scripts.js/wp-content/plugins/bcodecraft-submissions-cf7/assets/js/bccs-admin-scripts.js/wp-content/plugins/bcodecraft-submissions-cf7/assets/js/bccs-frontend-scripts.jsbcodecraft-submissions-cf7/assets/css/bccs-admin-styles.css?ver=bcodecraft-submissions-cf7/assets/js/bccs-admin-scripts.js?ver=bcodecraft-submissions-cf7/assets/js/bccs-frontend-scripts.js?ver=HTML / DOM Fingerprints
bccs-admin-notice<!-- BCodeCraft Submissions for Contact Form 7 --><!-- Plugin security and environment checks --><!-- Environment Compatibility Checks --><!-- Display admin notice for environment errors -->+1 moreBCCS_AJAX_URLBCCS_NONCEBCCS_PLUGIN_SLUG