
CF7 Advanced DatePicker Security & Risk Analysis
wordpress.org/plugins/cf7-advanced-datepickerA simple Contact Forms 7 DatePicker alternative.
Is CF7 Advanced DatePicker Safe to Use in 2026?
Generally Safe
Score 85/100CF7 Advanced DatePicker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cf7-advanced-datepicker" vv1.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries utilizing prepared statements, and a lack of file operations or external HTTP requests are all positive indicators. Furthermore, the plugin has no recorded vulnerabilities (CVEs) in its history, suggesting a history of responsible development and maintenance. The attack surface appears minimal with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not properly secured.
However, a significant concern arises from the output escaping results. With one total output and 0% properly escaped, this indicates a potential for cross-site scripting (XSS) vulnerabilities. Any data that is rendered to the user interface without proper sanitization could be exploited by attackers. While taint analysis shows no critical or high severity flows, this is likely due to the limited scope of the analysis or the absence of complex data handling that would trigger taint detection. The lack of nonce and capability checks on entry points, though currently zero, could become a risk if new entry points are introduced without appropriate security measures.
In conclusion, while the plugin demonstrates good practices in several key areas and has a clean vulnerability history, the lack of output escaping represents a notable weakness that needs immediate attention. This issue could expose users to XSS attacks. The absence of nonce and capability checks on entry points also warrants caution for future development.
Key Concerns
- 0% output escaping
CF7 Advanced DatePicker Security Vulnerabilities
CF7 Advanced DatePicker Code Analysis
Output Escaping
CF7 Advanced DatePicker Attack Surface
WordPress Hooks 3
Maintenance & Trust
CF7 Advanced DatePicker Maintenance & Trust
Maintenance Signals
Community Trust
CF7 Advanced DatePicker Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 – Dynamic Text Extension
contact-form-7-dynamic-text-extension
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
CF7 Advanced DatePicker Developer Profile
2 plugins · 210 total installs
How We Detect CF7 Advanced DatePicker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-advanced-datepicker/js/custom-script.js/wp-content/plugins/cf7-advanced-datepicker/css/jquery-ui.css/wp-content/plugins/cf7-advanced-datepicker/css/cf7-styles.css/wp-content/plugins/cf7-advanced-datepicker/js/custom-script.jscf7-advanced-datepicker/js/custom-script.js?ver=cf7-advanced-datepicker/css/jquery-ui.css?ver=cf7-advanced-datepicker/css/cf7-styles.css?ver=HTML / DOM Fingerprints
cf7-wrapname="cf7dp_effect"name="cf7dp_monyearmenu"name="cf7dp_show_week"name="cf7dp_date"setting