
Autosaver for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/cf7-autosaverAuto-save selected Contact Form 7 and Auto-fill them by Facebook!
Is Autosaver for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100Autosaver for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cf7-autosaver" v1.0.1 plugin demonstrates a strong security posture based on the provided static analysis. The plugin appears to have no direct attack surface via AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, all identified entry points (though zero) are noted as protected. The code analysis shows no use of dangerous functions and all SQL queries utilize prepared statements, indicating good development practices for data handling and preventing SQL injection. Output escaping is also largely handled correctly, with only a small percentage of outputs potentially not being properly escaped, which is a minor concern. The complete lack of vulnerability history is a significant positive indicator, suggesting the plugin has not historically been a target or has been developed with security in mind. However, the absence of nonce checks and capability checks, coupled with zero taint analysis flows, could be due to the plugin's lack of interactive features, but it's a potential area to scrutinize if functionality expands.
The plugin's strengths lie in its seemingly minimal attack surface, secure data querying, and lack of past vulnerabilities. The main areas for improvement, although not critically flagged in this analysis, would be to ensure all outputs are rigorously escaped and to consider implementing capability checks if any user-initiated actions are present, even if not exposed through typical entry points. The absence of taint analysis flows doesn't necessarily mean there are no vulnerabilities, but rather that none were detected by the specific analysis performed. Overall, this plugin appears to be in a good security state, with the potential for minor enhancements.
Key Concerns
- No Nonce Checks
- No Capability Checks
- Minor Output Escaping Issues
Autosaver for Contact Form 7 Security Vulnerabilities
Autosaver for Contact Form 7 Code Analysis
Output Escaping
Autosaver for Contact Form 7 Attack Surface
WordPress Hooks 8
Maintenance & Trust
Autosaver for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Autosaver for Contact Form 7 Alternatives
Controls for Contact Form 7 (Redirects, Analytics & Tracking)
contact-form-7-extras
Analytics, tracking, redirects and storage for Contact Form 7.
Adsfox – tracking Pixel
ddt-tracking
The easy way to track Facebook events.
Complianz – GDPR/CCPA Cookie Consent
complianz-gdpr
Configure your Cookie Banner, Cookie Consent and Cookie Policy with our Wizard and Cookies Scan.
CookieYes – Cookie Banner for Cookie Consent (Easy to setup GDPR/CCPA Compliant Cookie Notice)
cookie-law-info
Easily set up cookie banner or notice in WordPress, and policy pages for compliance with global cookie laws (GDPR, DSGVO, RGPD, CCPA/CPRA, etc).
Cookie Notice & Compliance for GDPR / CCPA
cookie-notice
Cookie Notice allows you to you elegantly inform users that your site uses cookies and helps you comply with GDPR, CCPA and other data privacy laws.
Autosaver for Contact Form 7 Developer Profile
5 plugins · 8K total installs
How We Detect Autosaver for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-autosaver/assets/js/scripts.js/wp-content/plugins/cf7-autosaver/assets/js/sisyphus.min.js/wp-content/plugins/cf7-autosaver/assets/css/style.css/wp-content/plugins/cf7-autosaver/assets/js/scripts.js/wp-content/plugins/cf7-autosaver/assets/js/sisyphus.min.js/wp-content/plugins/cf7-autosaver/assets/js/scripts.js?ver=/wp-content/plugins/cf7-autosaver/assets/js/sisyphus.min.js?ver=HTML / DOM Fingerprints
cf7as