CF7 Advanced DatePicker Security & Risk Analysis

wordpress.org/plugins/cf7-advanced-datepicker

A simple Contact Forms 7 DatePicker alternative.

200 active installs vv1.0 PHP + WP 3.4+ Updated Sep 9, 2014
contact-form-7contact-form-7-date-picker
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is CF7 Advanced DatePicker Safe to Use in 2026?

Generally Safe

Score 85/100

CF7 Advanced DatePicker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "cf7-advanced-datepicker" vv1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries utilizing prepared statements, and a lack of file operations or external HTTP requests are all positive indicators. Furthermore, the plugin has no recorded vulnerabilities (CVEs) in its history, suggesting a history of responsible development and maintenance. The attack surface appears minimal with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not properly secured.

However, a significant concern arises from the output escaping results. With one total output and 0% properly escaped, this indicates a potential for cross-site scripting (XSS) vulnerabilities. Any data that is rendered to the user interface without proper sanitization could be exploited by attackers. While taint analysis shows no critical or high severity flows, this is likely due to the limited scope of the analysis or the absence of complex data handling that would trigger taint detection. The lack of nonce and capability checks on entry points, though currently zero, could become a risk if new entry points are introduced without appropriate security measures.

In conclusion, while the plugin demonstrates good practices in several key areas and has a clean vulnerability history, the lack of output escaping represents a notable weakness that needs immediate attention. This issue could expose users to XSS attacks. The absence of nonce and capability checks on entry points also warrants caution for future development.

Key Concerns

  • 0% output escaping
Vulnerabilities
None known

CF7 Advanced DatePicker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CF7 Advanced DatePicker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

CF7 Advanced DatePicker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_enqueue_scriptscf7-datepicker.php:24
actionadmin_enqueue_scriptscf7-datepicker.php:64
actionadmin_menucf7-datepicker.php:73
Maintenance & Trust

CF7 Advanced DatePicker Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 9, 2014
PHP min version
Downloads10K

Community Trust

Rating94/100
Number of ratings3
Active installs200
Developer Profile

CF7 Advanced DatePicker Developer Profile

Ajit Kumar Satpathy

2 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CF7 Advanced DatePicker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-advanced-datepicker/js/custom-script.js/wp-content/plugins/cf7-advanced-datepicker/css/jquery-ui.css/wp-content/plugins/cf7-advanced-datepicker/css/cf7-styles.css
Script Paths
/wp-content/plugins/cf7-advanced-datepicker/js/custom-script.js
Version Parameters
cf7-advanced-datepicker/js/custom-script.js?ver=cf7-advanced-datepicker/css/jquery-ui.css?ver=cf7-advanced-datepicker/css/cf7-styles.css?ver=

HTML / DOM Fingerprints

CSS Classes
cf7-wrap
Data Attributes
name="cf7dp_effect"name="cf7dp_monyearmenu"name="cf7dp_show_week"name="cf7dp_date"
JS Globals
setting
FAQ

Frequently Asked Questions about CF7 Advanced DatePicker