Integration of Bitrix24 with Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/cf7-bitrix24-integration

Плагин для интеграции Битрикс24 с контактной формой 7.

600 active installs v2.1.5 PHP 5.6+ WP 5.0+ Updated Nov 21, 2025
bitrixbitrix24cf7contact-form-7integration
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Integration of Bitrix24 with Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Integration of Bitrix24 with Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "cf7-bitrix24-integration" v2.1.5 plugin exhibits a mixed security posture. While the absence of known CVEs and a generally good utilization of prepared statements for SQL queries and output escaping are positive indicators, significant concerns arise from the static analysis. The plugin exposes a total of 3 AJAX handlers, with 2 of them lacking proper authentication checks. This directly translates to potential unauthorized access and execution of sensitive functionalities if these handlers can be triggered by unauthenticated users.

Taint analysis shows zero critical or high severity flows, which is a strong positive. Furthermore, the plugin doesn't bundle any external libraries, mitigating risks associated with outdated or vulnerable components. The vulnerability history being clean suggests a reasonably well-maintained codebase. However, the identified unprotected AJAX endpoints are a critical weakness that could be exploited. The presence of capability checks and nonce checks for some entry points indicates an awareness of security best practices, but the incomplete implementation leaves a significant gap.

In conclusion, the plugin has strengths in its clean vulnerability history and absence of critical taint issues. Nevertheless, the unprotected AJAX endpoints represent a notable risk. Addressing these unauthenticated entry points should be the immediate priority for improving the plugin's overall security posture. The good rate of prepared statements and output escaping are commendable but do not fully compensate for the direct exposure of sensitive functionalities.

Key Concerns

  • Unprotected AJAX handlers
  • Limited nonce checks on AJAX
  • SQL queries without prepared statements (11%)
  • Outputs without proper escaping (21%)
Vulnerabilities
None known

Integration of Bitrix24 with Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Integration of Bitrix24 with Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
8 prepared
Unescaped Output
39
151 escaped
Nonce Checks
3
Capability Checks
6
File Operations
6
External Requests
11
Bundled Libraries
0

SQL Query Safety

89% prepared9 total queries

Output Escaping

79% escaped190 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
renderMappingPage (aos-cf7-bx24.php:306)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Integration of Bitrix24 with Contact Form 7 Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 3

authwp_ajax_cf7_bx24_webhook_handlerwoocommerce_integration_core.php:504
noprivwp_ajax_cf7_bx24_webhook_handlerwoocommerce_integration_core.php:505
authwp_ajax_cf7_bx24_bulk_sync_orderswoocommerce_integration_core.php:1211
WordPress Hooks 20
actionadmin_menuaos-cf7-bx24.php:55
actionadmin_initaos-cf7-bx24.php:56
actionwpcf7_form_elementsaos-cf7-bx24.php:57
actionwpcf7_before_send_mailaos-cf7-bx24.php:58
actionadmin_enqueue_scriptsaos-cf7-bx24.php:59
actioncf7_bx24_process_queueaos-cf7-bx24.php:66
actioninitaos-cf7-bx24.php:71
actionadmin_menuaos-cf7-bx24.php:77
actionadmin_menuaos-cf7-bx24.php:85
actionadmin_menuaos-cf7-bx24.php:91
filtercron_schedulesaos-cf7-bx24.php:897
actioninitwoocommerce_integration_core.php:37
actionwoocommerce_new_orderwoocommerce_integration_core.php:496
actionwoocommerce_order_status_changedwoocommerce_integration_core.php:497
actioncf7_bx24_sync_woocommerce_orderwoocommerce_integration_core.php:500
actioncf7_bx24_sync_order_status_changewoocommerce_integration_core.php:501
actioninitwoocommerce_integration_core.php:764
actionadmin_initwoocommerce_integration_core.php:765
actionadmin_menuwoocommerce_integration_core.php:1210
actionadmin_noticeswoocommerce_integration_core.php:1217

Scheduled Events 6

cf7_bx24_process_queue
cf7_bx24_process_queue
cf7_bx24_sync_woocommerce_order
cf7_bx24_sync_order_status_change
cf7_bx24_process_webhook
cf7_bx24_sync_woocommerce_order
Maintenance & Trust

Integration of Bitrix24 with Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 21, 2025
PHP min version5.6
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs600
Developer Profile

Integration of Bitrix24 with Contact Form 7 Developer Profile

Alex Osmanov

1 plugin · 600 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Integration of Bitrix24 with Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-bitrix24-integration/css/style.css/wp-content/plugins/cf7-bitrix24-integration/js/script.js
Script Paths
/wp-content/plugins/cf7-bitrix24-integration/js/script.js
Version Parameters
cf7-bitrix24-integration/style.css?ver=cf7-bitrix24-integration/script.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Generated by CF7 Bitrix24 Integration plugin -->
JS Globals
cf7_bx24_settings
FAQ

Frequently Asked Questions about Integration of Bitrix24 with Contact Form 7