
Contact Form 7 – Blacklist Unwanted Email Security & Risk Analysis
wordpress.org/plugins/block-email-cf7This is a free add-on plugin for contact form 7, which validates the email field and restrict unwanted email submission as well as allowed only busine …
Is Contact Form 7 – Blacklist Unwanted Email Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form 7 – Blacklist Unwanted Email has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "block-email-cf7" plugin version 1.1.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any identified vulnerabilities in its history is a significant positive indicator. The static analysis reveals a remarkably small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, none of these entry points are unprotected. Furthermore, the code signals show no dangerous functions, file operations, or external HTTP requests, and critically, no nonce or capability checks are required, suggesting that the plugin might not handle sensitive operations or user input in a way that necessitates these checks.
However, the presence of a single SQL query that does not use prepared statements is a concern, even if it's only one instance. While no critical or high severity taint flows were detected, this specific SQL query represents a potential for SQL injection if the input feeding it is not rigorously sanitized upstream. The output escaping is also not perfect, with 33% of outputs not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities. Despite these minor concerns, the overall picture is one of a well-developed plugin with a low risk profile, especially given its clean vulnerability history.
Key Concerns
- Raw SQL query without prepared statement
- Unescaped output detected
Contact Form 7 – Blacklist Unwanted Email Security Vulnerabilities
Contact Form 7 – Blacklist Unwanted Email Code Analysis
SQL Query Safety
Output Escaping
Contact Form 7 – Blacklist Unwanted Email Attack Surface
WordPress Hooks 13
Maintenance & Trust
Contact Form 7 – Blacklist Unwanted Email Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 – Blacklist Unwanted Email Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
contact-form-7-honeypot
Addons for Contact Form 7 — Honeypot, Database Entries, Redirection, Spam Protection, Webhooks, ACF integration for Contact Form 7, and more.
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Advanced Contact form 7 DB
advanced-cf7-db
Save all contact form 7 form submitted data to the database, View, Ordering, Change field labels and Import/Export data using CSV.
Connect Contact Form 7 and Mailchimp
contact-form-7-mailchimp-extension
Connect Contact Form 7 to Mailchimp. Automatically sync form submissions to your Mailchimp audiences with merge field mapping, double opt-in, and opt- …
Contact Form 7 – Blacklist Unwanted Email Developer Profile
2 plugins · 500 total installs
How We Detect Contact Form 7 – Blacklist Unwanted Email
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-email-cf7/css/style.css