
Conversational Form Add-on For Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/cf7-bot-forms-add-onThis WordPress plugin integrates Contact Form 7 forms into Conversational Form.
Is Conversational Form Add-on For Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100Conversational Form Add-on For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "cf7-bot-forms-add-on" v1.2 plugin presents a mixed bag of good practices and significant concerns. On the positive side, the plugin demonstrates adherence to secure SQL practices by using prepared statements exclusively. Furthermore, it has no recorded vulnerabilities, which suggests a history of responsible development or a lack of past exploitation. However, the static analysis reveals critical weaknesses that overshadow these strengths.
The plugin's code analysis flags two instances of the `unserialize` function, which is notoriously dangerous as it can lead to Remote Code Execution if processing untrusted input. Compounding this, the taint analysis reveals two flows with unsanitized paths, both classified as high severity. This indicates that user-controlled data is likely being passed directly to the dangerous `unserialize` function or other vulnerable operations without proper sanitization, creating a direct pathway for exploitation.
The absence of nonce checks and capability checks on any entry points, combined with a low percentage of properly escaped output, further exacerbates these risks. While the static attack surface appears small (0 AJAX handlers, 0 REST API routes, etc.), the presence of internal code vulnerabilities means these don't need to be exposed externally to be dangerous. The lack of external HTTP requests is a minor positive, but the internal security flaws are the primary concern. In conclusion, despite a clean vulnerability history, the critical findings in code and taint analysis, particularly the use of `unserialize` with unsanitized input, make this plugin a high-risk component.
Key Concerns
- High severity taint flow
- High severity taint flow
- Dangerous function used: unserialize
- Dangerous function used: unserialize
- Low output escaping percentage
- No nonce checks
- No capability checks
Conversational Form Add-on For Contact Form 7 Security Vulnerabilities
Conversational Form Add-on For Contact Form 7 Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Conversational Form Add-on For Contact Form 7 Attack Surface
WordPress Hooks 6
Maintenance & Trust
Conversational Form Add-on For Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Conversational Form Add-on For Contact Form 7 Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
CF7 Apps – Honeypot, Database, Redirection, Webhook, and Addons for Contact Form 7
contact-form-7-honeypot
Addons for Contact Form 7 — Honeypot, Database Entries, Redirection, Spam Protection, Webhooks, ACF integration for Contact Form 7, and more.
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Advanced Contact form 7 DB
advanced-cf7-db
Save all contact form 7 form submitted data to the database, View, Ordering, Change field labels and Import/Export data using CSV.
Connect Contact Form 7 and Mailchimp
contact-form-7-mailchimp-extension
Connect Contact Form 7 to Mailchimp. Automatically sync form submissions to your Mailchimp audiences with merge field mapping, double opt-in, and opt- …
Conversational Form Add-on For Contact Form 7 Developer Profile
1 plugin · 10 total installs
How We Detect Conversational Form Add-on For Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-bot-forms-add-on/assets/css/styles.css/wp-content/plugins/cf7-bot-forms-add-on/assets/gform/conversational-form.min.css/wp-content/plugins/cf7-bot-forms-add-on/assets/gform/conversational-form.min.js/wp-content/plugins/cf7-bot-forms-add-on/assets/js/scripts.js/wp-content/plugins/cf7-bot-forms-add-on/assets/js/scripts.js/wp-content/plugins/cf7-bot-forms-add-on/assets/gform/conversational-form.min.jscf7-bot-forms-add-on/assets/css/styles.css?ver=cf7-bot-forms-add-on/assets/js/scripts.js?ver=HTML / DOM Fingerprints
cf7bot-conversational-formconversational-form-wrapperconversational-form-messageconversational-form-input-areacf7bot_hs_fieldcf7bot_cf7_fieldadd_fieldremove_fielddata-form-iddata-form-outerdata-bot-icondata-user-icondata-enabledcf7bot_get_view_templatecf7bot_root_urlcf7bot_root_dircf7bot_admin_save_formcf7bot_admin_panel_contentcf7bot_admin_panel<div class="cf7bot-conversational-form" data-form-id="conversational-form-wrapperconversational-form-messageconversational-form-input-area