CleverReach Integration for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/cf7-cleverreach-integration

Connect your Contact Form 7 forms with your CleverReach account.

700 active installs v2.4.9 PHP 7.4+ WP 4.6+ Updated Aug 29, 2022
cf7cleverreachcontact-form-7contact-form-7-addoncontact-form-7-integration
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is CleverReach Integration for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

CleverReach Integration for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The cf7-cleverreach-integration v2.4.9 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no known vulnerabilities recorded in its history. The absence of external HTTP requests and critical/high severity taint flows also contributes to a seemingly robust foundation.

However, significant concerns arise from the static analysis. The presence of one AJAX handler without authentication checks presents a direct attack vector. This unprotected entry point, coupled with the lack of comprehensive output escaping (only 23% properly escaped), suggests a potential for cross-site scripting (XSS) vulnerabilities or other injection attacks that could be leveraged through this AJAX handler. Furthermore, the absence of nonce checks on this handler exacerbates the risk, making it easier for attackers to trigger actions.

While the plugin has no recorded vulnerabilities, this can sometimes be indicative of a lack of thorough past security auditing or a low profile that hasn't attracted attackers. The identified unprotected AJAX handler and poor output escaping are concrete code-level weaknesses that should be prioritized for remediation to improve the plugin's overall security. The bundled Guzzle library, while not explicitly flagged as outdated, warrants attention in future audits.

Key Concerns

  • Unprotected AJAX handler
  • Low percentage of properly escaped output
  • Missing nonce checks on AJAX
Vulnerabilities
None known

CleverReach Integration for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CleverReach Integration for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
7 escaped
Nonce Checks
0
Capability Checks
1
File Operations
3
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

23% escaped31 total outputs
Attack Surface
1 unprotected

CleverReach Integration for Contact Form 7 Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_dismiss_admin_notificationvendor-prefixed\pxlrbt\wordpress-notifier\src\Notifier.php:51
WordPress Hooks 8
actionwpcf7_save_contact_formclasses\Controllers\FormConfigController.php:16
filterwpcf7_editor_panelsclasses\Controllers\FormConfigController.php:17
actionadmin_menuclasses\Controllers\SettingsPageController.php:20
actioninitclasses\Plugin.php:31
actiondelete_postclasses\Plugin.php:32
actionwpcf7_mail_sentclasses\Plugin.php:35
actionadmin_noticesvendor-prefixed\pxlrbt\wordpress-notifier\src\Notifier.php:50
actionadmin_footervendor-prefixed\pxlrbt\wordpress-notifier\src\Notifier.php:52
Maintenance & Trust

CleverReach Integration for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 29, 2022
PHP min version7.4
Downloads17K

Community Trust

Rating100/100
Number of ratings9
Active installs700
Developer Profile

CleverReach Integration for Contact Form 7 Developer Profile

pixelarbeit

2 plugins · 710 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CleverReach Integration for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-cleverreach-integration/assets/css/admin.css/wp-content/plugins/cf7-cleverreach-integration/assets/js/admin.js
Script Paths
/wp-content/plugins/cf7-cleverreach-integration/assets/js/admin.js
Version Parameters
cf7-cleverreach-integration/assets/css/admin.css?ver=cf7-cleverreach-integration/assets/js/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
name="_wpcf7-cleverreach-options"name="_wpcf7-cleverreach-attribute-mapping"name="_wpcf7-cleverreach-global-attribute-mapping"
FAQ

Frequently Asked Questions about CleverReach Integration for Contact Form 7