HTML Editor for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/cf7-coder

Add HTML editor to Contact Form 7 with code highlighter and extended form options.

1K active installs v1.0.1 PHP 7.4+ WP 5.0+ Updated Jan 26, 2026
cf7code-editorcontact-form-7html-editorredirect
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HTML Editor for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

HTML Editor for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The 'cf7-coder' plugin v1.0.1 demonstrates a strong security posture based on the provided static analysis. It exhibits excellent practices by having no known vulnerabilities, a clean code signal report with no dangerous functions or file operations, and a complete absence of external HTTP requests. All SQL queries are prepared, and all output is properly escaped, indicating robust defenses against common web attacks. The taint analysis also shows no critical or high severity flows, which is a very positive sign.

However, a single flow with an unsanitized path detected in the taint analysis warrants attention, even if not classified as critical. This could potentially be a vector for directory traversal or other path manipulation attacks if exploited in conjunction with other factors, although the lack of other vulnerabilities and a limited attack surface mitigates this risk. The absence of nonce checks and capability checks across its attack surface (which is currently zero) means that if any new entry points were introduced without proper security measures, they would be a significant risk.

Overall, 'cf7-coder' appears to be a very secure plugin. Its vulnerability history is nonexistent, suggesting a proactive approach to security or simply a lack of discovery due to its limited footprint. The primary area for improvement would be to investigate and sanitize the identified unsanitized path flow, and to ensure any future additions to the attack surface include robust authentication and authorization checks.

Key Concerns

  • Flow with unsanitized path
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

HTML Editor for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

HTML Editor for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
25 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped25 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
wpcf7_add_test_mode (cf7-coder.php:68)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

HTML Editor for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_enqueue_scriptscf7-coder.php:29
actionwpcf7_admin_misc_pub_sectioncf7-coder.php:30
filterwpcf7_contact_form_propertiescf7-coder.php:31
actionwpcf7_save_contact_formcf7-coder.php:32
filterdo_shortcode_tagcf7-coder.php:33
actionwp_enqueue_scriptscf7-coder.php:37
actionplugins_loadedcf7-coder.php:639
actionadmin_noticesclass.wpcf7coder-extension-activation.php:73
Maintenance & Trust

HTML Editor for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 26, 2026
PHP min version7.4
Downloads11K

Community Trust

Rating100/100
Number of ratings2
Active installs1K
Developer Profile

HTML Editor for Contact Form 7 Developer Profile

Wow-Company

25 plugins · 98K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect HTML Editor for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-coder/assets/style.css/wp-content/plugins/cf7-coder/assets/material.css/wp-content/plugins/cf7-coder/assets/script.js
Script Paths
/wp-content/plugins/cf7-coder/assets/script.js
Version Parameters
cf7-coder/assets/style.css?ver=cf7-coder/assets/material.css?ver=cf7-coder/assets/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpcf7-test-modewpcf7-remove-auto-tagswpcf7-load-assetswpcf7-redirectwpcf7-hide-formwpcf7-remove-refillwpcf7-disable-submit
Data Attributes
data-tooltip
FAQ

Frequently Asked Questions about HTML Editor for Contact Form 7