
Calculation For Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/calculation-for-contact-form-7Contact Form 7 Calculator make calculations between each field without reloading its work. It can be making a cost calculator for contact form 7.
Is Calculation For Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100Calculation For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "calculation-for-contact-form-7" v1.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code signals indicate a commendable approach to security with no dangerous functions, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests. The lack of any recorded CVEs or past vulnerabilities further bolsters this positive assessment, suggesting a history of responsible development or a lack of discovered issues.
However, there are areas that warrant attention. The relatively low percentage of properly escaped output (63%) suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care in the remaining outputs. Additionally, the complete absence of nonce checks and capability checks, while not directly exploitable due to the limited attack surface, represents a missed opportunity to implement standard WordPress security practices. This could become a concern if the plugin's functionality were to expand or if new entry points were introduced in future versions without these checks.
In conclusion, the plugin appears safe to use in its current version, primarily due to its minimal attack surface and secure handling of data operations like SQL. The main concern lies in the potential for XSS due to incomplete output escaping. While the lack of checks like nonces and capabilities is not an immediate risk, it is a deviation from best practices that could be addressed in future development.
Key Concerns
- Output escaping not fully implemented
- Missing nonce checks
- Missing capability checks
Calculation For Contact Form 7 Security Vulnerabilities
Calculation For Contact Form 7 Release Timeline
Calculation For Contact Form 7 Code Analysis
Output Escaping
Calculation For Contact Form 7 Attack Surface
WordPress Hooks 10
Maintenance & Trust
Calculation For Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Calculation For Contact Form 7 Alternatives
No alternatives data available yet.
Calculation For Contact Form 7 Developer Profile
21 plugins · 11K total installs
How We Detect Calculation For Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/calculation-for-contact-form-7/assets/css/front.css/wp-content/plugins/calculation-for-contact-form-7/assets/js/front.js/wp-content/plugins/calculation-for-contact-form-7/assets/js/admin.js/wp-content/plugins/calculation-for-contact-form-7/assets/js/front.js/wp-content/plugins/calculation-for-contact-form-7/assets/js/admin.jscalculation-for-contact-form-7/assets/css/front.css?ver=calculation-for-contact-form-7/assets/js/front.js?ver=calculation-for-contact-form-7/assets/js/admin.js?ver=HTML / DOM Fingerprints
calculationcf7_pro_msgdata-tag-partdata-tag-option<header class="description-box"><h3>calculator form tag generator</h3></header><div class="control-box"><input type="hidden" data-tag-part="basetype" value="calculator" ><input type="text" data-tag-part="name" pattern="[A-Za-z][A-Za-z0-9_\-]*">