
CleverReach Integration for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/cf7-cleverreach-integrationConnect your Contact Form 7 forms with your CleverReach account.
Is CleverReach Integration for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100CleverReach Integration for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cf7-cleverreach-integration v2.4.9 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no known vulnerabilities recorded in its history. The absence of external HTTP requests and critical/high severity taint flows also contributes to a seemingly robust foundation.
However, significant concerns arise from the static analysis. The presence of one AJAX handler without authentication checks presents a direct attack vector. This unprotected entry point, coupled with the lack of comprehensive output escaping (only 23% properly escaped), suggests a potential for cross-site scripting (XSS) vulnerabilities or other injection attacks that could be leveraged through this AJAX handler. Furthermore, the absence of nonce checks on this handler exacerbates the risk, making it easier for attackers to trigger actions.
While the plugin has no recorded vulnerabilities, this can sometimes be indicative of a lack of thorough past security auditing or a low profile that hasn't attracted attackers. The identified unprotected AJAX handler and poor output escaping are concrete code-level weaknesses that should be prioritized for remediation to improve the plugin's overall security. The bundled Guzzle library, while not explicitly flagged as outdated, warrants attention in future audits.
Key Concerns
- Unprotected AJAX handler
- Low percentage of properly escaped output
- Missing nonce checks on AJAX
CleverReach Integration for Contact Form 7 Security Vulnerabilities
CleverReach Integration for Contact Form 7 Code Analysis
Bundled Libraries
Output Escaping
CleverReach Integration for Contact Form 7 Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
CleverReach Integration for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
CleverReach Integration for Contact Form 7 Alternatives
WeClapp Integration for Contact Form 7
cf7-weclapp-integration
Send user form input to WeClapp to add new contacts/leads/customers recipients.
GSheetConnector for CF7 – Connect Contact Form 7 to Google Sheets and Send Form Submissions in Real Time
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
CF7 Notie
cf7-notie
Display Contact Form 7 response messages as an alternative the standard alert dialog.
CF7 LACRM Connector
lacrm-connector-for-contact-form7
Send your Contact Form 7 data directly to your Less Annoying CRM account.
CleverReach Integration for Contact Form 7 Developer Profile
2 plugins · 710 total installs
How We Detect CleverReach Integration for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-cleverreach-integration/assets/css/admin.css/wp-content/plugins/cf7-cleverreach-integration/assets/js/admin.js/wp-content/plugins/cf7-cleverreach-integration/assets/js/admin.jscf7-cleverreach-integration/assets/css/admin.css?ver=cf7-cleverreach-integration/assets/js/admin.js?ver=HTML / DOM Fingerprints
name="_wpcf7-cleverreach-options"name="_wpcf7-cleverreach-attribute-mapping"name="_wpcf7-cleverreach-global-attribute-mapping"