Submissions Capture & Exporter for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/bulbul-capture-exporter-for-contact-form-7

Capture Contact Form 7 submissions to database. View, search, delete & export to CSV via modern admin modals.

0 active installs v1.0.6 PHP 7.4+ WP 6.0+ Updated Unknown
cf7-addonscontact-form-7csvexportsubmissions
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Submissions Capture & Exporter for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Submissions Capture & Exporter for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The bulbul-capture-exporter-for-contact-form-7 plugin v1.0.6 exhibits a generally strong security posture based on the static analysis. The absence of any critical or high-severity issues in taint analysis, coupled with a high percentage of prepared SQL statements and properly escaped output, indicates good development practices. The plugin also implements nonce checks and capability checks on its AJAX handlers, which are essential for preventing common web vulnerabilities. The complete lack of any recorded vulnerabilities in its history further reinforces this positive outlook.

However, there are a couple of areas that warrant attention. While the total number of entry points (AJAX handlers) is moderate, the fact that none of them were identified as having authentication checks (0 without auth checks) is a potential concern. Although the static analysis didn't find specific issues here, it suggests that the plugin might be relying on WordPress's default user capabilities for protection, which could be less secure than explicit checks. Additionally, the presence of file operations, even without reported issues, always carries a degree of risk, and it's important to ensure these are handled with extreme care and input validation. The lack of external HTTP requests is a positive sign, reducing the risk of SSRF vulnerabilities.

In conclusion, bulbul-capture-exporter-for-contact-form-7 v1.0.6 appears to be a secure plugin with a robust codebase and no known historical vulnerabilities. The development team seems to prioritize security. The minor concerns around the authentication checks on AJAX handlers and file operations should be monitored, but they do not represent immediate critical threats based on the provided data.

Key Concerns

  • AJAX handlers without explicit auth checks
Vulnerabilities
None known

Submissions Capture & Exporter for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Submissions Capture & Exporter for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
12 prepared
Unescaped Output
3
52 escaped
Nonce Checks
6
Capability Checks
2
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

92% prepared13 total queries

Output Escaping

95% escaped55 total outputs
Data Flows
All sanitized

Data Flow Analysis

5 flows
ajax_load_settings (includes\class-subce-admin.php:161)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Submissions Capture & Exporter for Contact Form 7 Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 6

authwp_ajax_subce_load_settingsincludes\class-subce-admin.php:11
authwp_ajax_subce_save_settingsincludes\class-subce-admin.php:12
authwp_ajax_subce_load_entriesincludes\class-subce-admin.php:13
authwp_ajax_subce_delete_entryincludes\class-subce-admin.php:14
authwp_ajax_subce_export_csvincludes\class-subce-admin.php:15
authwp_ajax_subce_bulk_deleteincludes\class-subce-admin.php:16
WordPress Hooks 6
actionplugins_loadedbulbul-capture-exporter-for-contact-form-7.php:45
actionadmin_noticesbulbul-capture-exporter-for-contact-form-7.php:50
actionadmin_menuincludes\class-subce-admin.php:9
actionadmin_enqueue_scriptsincludes\class-subce-admin.php:10
actionadmin_footerincludes\class-subce-admin.php:17
actionwpcf7_before_send_mailincludes\class-subce-capture.php:9
Maintenance & Trust

Submissions Capture & Exporter for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads207

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Submissions Capture & Exporter for Contact Form 7 Developer Profile

bulbul389

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Submissions Capture & Exporter for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bulbul-capture-exporter-for-contact-form-7/assets/css/admin.css/wp-content/plugins/bulbul-capture-exporter-for-contact-form-7/assets/js/admin.js
Script Paths
/wp-content/plugins/bulbul-capture-exporter-for-contact-form-7/assets/js/admin.js
Version Parameters
bulbul-capture-exporter-for-contact-form-7/assets/css/admin.css?ver=bulbul-capture-exporter-for-contact-form-7/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
subce-gridsubce-form-cardsubce-card-headersubce-card-bodysubce-card-footersubce-open-entriessubce-open-settings
Data Attributes
data-form-id
JS Globals
subce_ajax
REST Endpoints
/wp-json/subce/v1/settings/wp-json/subce/v1/entries/wp-json/subce/v1/delete-entry/wp-json/subce/v1/export-csv/wp-json/subce/v1/bulk-delete
FAQ

Frequently Asked Questions about Submissions Capture & Exporter for Contact Form 7