
Contact Form 7: Add to Page Security & Risk Analysis
wordpress.org/plugins/cf7-add-to-pageA plugin that provides a drop-down of selectable forms for easy attachment to pages.
Is Contact Form 7: Add to Page Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form 7: Add to Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'cf7-add-to-page' plugin version 1.0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of detected dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), file operations, and external HTTP requests are positive indicators. Furthermore, the presence of nonce and capability checks suggests an awareness of security best practices for controlling access to functionalities. The vulnerability history shows no known CVEs, which is encouraging and implies a clean track record thus far.
However, the static analysis does reveal a minor concern regarding output escaping, with 25% of identified outputs not being properly escaped. While this is not a critical finding given the limited number of outputs, it represents a potential vector for cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these unescaped outputs. The lack of any identified taint flows or a large attack surface with unprotected entry points is a significant strength, indicating that the plugin is not readily exposed to common web attacks.
In conclusion, 'cf7-add-to-page' v1.0.1 is a reasonably secure plugin with a clean vulnerability history. The primary area for improvement lies in ensuring all output is properly escaped to mitigate potential XSS risks. The limited attack surface and presence of access control checks are commendable strengths.
Key Concerns
- Unescaped output identified
Contact Form 7: Add to Page Security Vulnerabilities
Contact Form 7: Add to Page Code Analysis
Output Escaping
Contact Form 7: Add to Page Attack Surface
WordPress Hooks 3
Maintenance & Trust
Contact Form 7: Add to Page Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7: Add to Page Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
GSheetConnector for CF7 – Connect Contact Form 7 to Google Sheets and Send Form Submissions in Real Time
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
Bootstrap for Contact Form 7
bootstrap-for-contact-form-7
This plugin modifies the output of the popular Contact Form 7 plugin to be styled in compliance with themes using the Bootstrap CSS framework.
Contact Form 7 – Success Page Redirects
contact-form-7-success-page-redirects
An add-on for Contact Form 7 that provides a straightforward method to redirect visitors to success pages or thank you pages.
Contact Form 7: Accessible Defaults
contact-form-7-accessible-defaults
Replaces the default Contact Form 7 form with an accessible equivalent and provides a suite of selectable base forms.
Contact Form 7: Add to Page Developer Profile
3 plugins · 110 total installs
How We Detect Contact Form 7: Add to Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
post-attributes-label-wrapperpost-attributes-labelname="CF7_ID"id="CF7_ID"[contact-form-7 id=