
Billplz Addon for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/billplz-for-contact-form-7Integrates Billplz with Contact Form 7. Start accepting payment with Contact Form 7 & Billplz today.
Is Billplz Addon for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 99/100Billplz Addon for Contact Form 7 has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "billplz-for-contact-form-7" plugin, in version 1.2.1, presents a mixed security posture. On the positive side, the plugin demonstrates good practices by consistently using prepared statements for all SQL queries and a high percentage of properly escaped output. It also shows a relatively small attack surface with only one shortcode identified, and no unprotected entry points. The vulnerability history, while showing a past medium severity XSS, has no currently unpatched CVEs, suggesting active maintenance and patching.
However, several concerning signals emerge from the static analysis. The presence of three high-severity taint flows with unsanitized paths is a significant red flag, indicating potential injection vulnerabilities despite the absence of critical severity findings. The lack of nonce checks is also a notable weakness, especially if any of the identified entry points or file operations could be triggered maliciously without sufficient user authentication or validation. The single file operation and external HTTP request, without explicit mention of security checks, could also represent potential vectors if not handled carefully.
Overall, while the plugin has strengths in its handling of SQL and output escaping, the high-severity taint flows and the absence of nonce checks are significant areas of concern that require further investigation and mitigation. The historical medium severity XSS suggests a recurring pattern that warrants vigilance.
Key Concerns
- High severity taint flows
- Unsanitized paths in taint flows
- Missing nonce checks
- Low output escaping coverage
- File operations without clear auth context
- External HTTP requests without clear auth context
Billplz Addon for Contact Form 7 Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Billplz Addon for Contact Form 7 <= 1.2.0 - Reflected Cross-Site Scripting
Billplz Addon for Contact Form 7 Release Timeline
Billplz Addon for Contact Form 7 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Billplz Addon for Contact Form 7 Attack Surface
Shortcodes 1
WordPress Hooks 18
Maintenance & Trust
Billplz Addon for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Billplz Addon for Contact Form 7 Alternatives
FPX Payment for WPSmartPay (Billplz)
billplz-for-wpsmartpay
Accept payment in WPSmartPay by using Billplz.
Product Filter for WooCommerce by WBW
woo-product-filter
Filter products by categories, attributes, prices, and more. Elementor Compatibility. Shoppers easily find products with WooCommerce Product Filter
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
Pledged Plugins Secure Gateway for Authorize.net and WooCommerce
woo-authorize-net-gateway-aim
Authorize.net payment gateway integration for WooCommerce to accept credit cards directly on WordPress e-commerce websites.
Store Exporter – Export WooCommerce Products, Orders, Subscriptions, Customers
woocommerce-exporter
Export WooCommerce products, orders, customers, categories, tags, subscriptions & more into formatted files like CSV, XML, Excel 2007, XLS, XLSX.
Billplz Addon for Contact Form 7 Developer Profile
6 plugins · 130 total installs
How We Detect Billplz Addon for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/billplz-for-contact-form-7/assets/js/general-settings.jsgeneral-settings.js