
HTML Editor for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/cf7-coderAdd HTML editor to Contact Form 7 with code highlighter and extended form options.
Is HTML Editor for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100HTML Editor for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'cf7-coder' plugin v1.0.1 demonstrates a strong security posture based on the provided static analysis. It exhibits excellent practices by having no known vulnerabilities, a clean code signal report with no dangerous functions or file operations, and a complete absence of external HTTP requests. All SQL queries are prepared, and all output is properly escaped, indicating robust defenses against common web attacks. The taint analysis also shows no critical or high severity flows, which is a very positive sign.
However, a single flow with an unsanitized path detected in the taint analysis warrants attention, even if not classified as critical. This could potentially be a vector for directory traversal or other path manipulation attacks if exploited in conjunction with other factors, although the lack of other vulnerabilities and a limited attack surface mitigates this risk. The absence of nonce checks and capability checks across its attack surface (which is currently zero) means that if any new entry points were introduced without proper security measures, they would be a significant risk.
Overall, 'cf7-coder' appears to be a very secure plugin. Its vulnerability history is nonexistent, suggesting a proactive approach to security or simply a lack of discovery due to its limited footprint. The primary area for improvement would be to investigate and sanitize the identified unsanitized path flow, and to ensure any future additions to the attack surface include robust authentication and authorization checks.
Key Concerns
- Flow with unsanitized path
- Missing nonce checks
- Missing capability checks
HTML Editor for Contact Form 7 Security Vulnerabilities
HTML Editor for Contact Form 7 Code Analysis
Output Escaping
Data Flow Analysis
HTML Editor for Contact Form 7 Attack Surface
WordPress Hooks 8
Maintenance & Trust
HTML Editor for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
HTML Editor for Contact Form 7 Alternatives
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Contact Form 7 – Success Page Redirects
contact-form-7-success-page-redirects
An add-on for Contact Form 7 that provides a straightforward method to redirect visitors to success pages or thank you pages.
Extensions For CF7 (Contact form 7 Database, Conditional Fields and Redirection)
extensions-for-cf7
Easily save contact form data, apply conditional logic in the fields and redirect to any page after contact form submission.
Simple Redirection for Contact Form 7
simple-redirection-for-contact-form-7
Simple redirection addon for Contact Form 7, allows you to redirect to an existing page or a custom URL after form submission.
Simple Redirect – Contact Form 7
simple-redirect-contact-form-7
Redirect settings for Contact Form 7, Redirect after mail sent or form submit, Add settings line in form "Additional Settings" tab, on_mails …
HTML Editor for Contact Form 7 Developer Profile
25 plugins · 98K total installs
How We Detect HTML Editor for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-coder/assets/style.css/wp-content/plugins/cf7-coder/assets/material.css/wp-content/plugins/cf7-coder/assets/script.js/wp-content/plugins/cf7-coder/assets/script.jscf7-coder/assets/style.css?ver=cf7-coder/assets/material.css?ver=cf7-coder/assets/script.js?ver=HTML / DOM Fingerprints
wpcf7-test-modewpcf7-remove-auto-tagswpcf7-load-assetswpcf7-redirectwpcf7-hide-formwpcf7-remove-refillwpcf7-disable-submitdata-tooltip