Contact Form 7 Syntax Highlighting Security & Risk Analysis

wordpress.org/plugins/cf7-ace-syntax-highlighting

Adds syntax higlighting to the Contact Form 7 admin screens. Requires the Contact Form 7 plugin.

1K active installs v0.2.4 PHP + WP 4.0.1+ Updated May 19, 2020
contact-form-7contact-form-7-form-editorcontact-form-7-html-editorform-textareahtml-editor
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Contact Form 7 Syntax Highlighting Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 Syntax Highlighting has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'cf7-ace-syntax-highlighting' plugin version 0.2.4 exhibits an exceptionally strong security posture. The code analysis reveals no dangerous functions, no raw SQL queries, and all output is properly escaped. Furthermore, there are no observed file operations or external HTTP requests, indicating a well-contained plugin. The complete absence of AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the attack surface. Crucially, there are no recorded vulnerabilities (CVEs) for this plugin, and the taint analysis found no issues. This suggests the developers have implemented robust security practices, including comprehensive input validation and sanitization, leading to a highly secure plugin.

Vulnerabilities
None known

Contact Form 7 Syntax Highlighting Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form 7 Syntax Highlighting Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Contact Form 7 Syntax Highlighting Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_enqueue_scriptscontact-form-7-ace-syntax.php:11
Maintenance & Trust

Contact Form 7 Syntax Highlighting Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 19, 2020
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings6
Active installs1K
Developer Profile

Contact Form 7 Syntax Highlighting Developer Profile

Joris van Montfort

5 plugins · 4K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
27 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 Syntax Highlighting

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-ace-syntax-highlighting/js/ace/ace.js/wp-content/plugins/cf7-ace-syntax-highlighting/js/cf7_ace_init.js
Script Paths
js/ace/ace.jsjs/cf7_ace_init.js
Version Parameters
cf7-ace-syntax-highlighting/js/ace/ace.js?ver=cf7-ace-syntax-highlighting/js/cf7_ace_init.js?ver=

HTML / DOM Fingerprints

JS Globals
ace
FAQ

Frequently Asked Questions about Contact Form 7 Syntax Highlighting