Contact Form 7 Cost Calculator (Add-on for CF7) Security & Risk Analysis

wordpress.org/plugins/cf7-cost-calculator

Contact Form 7 Cost Calculator is a clean, simple quote / project price / estimation plugin which allows you to easily create price estimation contact …

90 active installs v1.0.0 PHP 5.0+ WP 3.0+ Updated Mar 24, 2019
azmarketcf7-cost-calculatorcontact-form-7cost-calculator
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form 7 Cost Calculator (Add-on for CF7) Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 Cost Calculator (Add-on for CF7) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "cf7-cost-calculator" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerabilities or CVEs, suggesting a relatively stable and well-maintained code base in its history. There are also no reported issues with dangerous functions, file operations, external HTTP requests, or bundled libraries.

However, significant concerns arise from the static analysis. The plugin has a total of one entry point, an AJAX handler, which critically lacks any authentication or capability checks. This directly exposes a significant part of the plugin's functionality to unauthenticated users, creating a substantial attack surface. Furthermore, while the majority of output is properly escaped, a notable percentage (36%) is not, which could lead to Cross-Site Scripting (XSS) vulnerabilities if the unsanitized data originates from user input.

The lack of taint analysis results is neutral; it doesn't confirm safety but doesn't highlight specific flaws either. The absence of nonce checks on the identified AJAX handler is a critical oversight. In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the unprotected AJAX handler and potential for unescaped output present immediate and significant security risks that require urgent attention.

Key Concerns

  • AJAX handler without authentication checks
  • Significant portion of output not properly escaped
  • Missing nonce checks on AJAX handler
Vulnerabilities
None known

Contact Form 7 Cost Calculator (Add-on for CF7) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form 7 Cost Calculator (Add-on for CF7) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
28 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

64% escaped44 total outputs
Attack Surface
1 unprotected

Contact Form 7 Cost Calculator (Add-on for CF7) Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_cf7cc_save_formulasinc\admin.php:21
WordPress Hooks 7
actionadmin_noticescost-calculator.php:41
actionplugins_loadedcost-calculator.php:67
filterwpcf7_editor_panelsinc\admin.php:16
actionadmin_footerinc\admin.php:17
actionadmin_enqueue_scriptsinc\admin.php:18
actionwpcf7_initinc\frontend.php:8
actionwp_enqueue_scriptsinc\frontend.php:9
Maintenance & Trust

Contact Form 7 Cost Calculator (Add-on for CF7) Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMar 24, 2019
PHP min version5.0
Downloads4K

Community Trust

Rating40/100
Number of ratings1
Active installs90
Developer Profile

Contact Form 7 Cost Calculator (Add-on for CF7) Developer Profile

azmarket

4 plugins · 140 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 Cost Calculator (Add-on for CF7)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-cost-calculator/assets/admin/magnific-popup.css/wp-content/plugins/cf7-cost-calculator/assets/admin/admin.css/wp-content/plugins/cf7-cost-calculator/assets/admin/jquery.magnific-popup.min.js/wp-content/plugins/cf7-cost-calculator/assets/admin/autosize.min.js/wp-content/plugins/cf7-cost-calculator/assets/admin/admin.js
Script Paths
/wp-content/plugins/cf7-cost-calculator/assets/admin/jquery.magnific-popup.min.js/wp-content/plugins/cf7-cost-calculator/assets/admin/autosize.min.js/wp-content/plugins/cf7-cost-calculator/assets/admin/admin.js
Version Parameters
cf7-cost-calculator/assets/admin/magnific-popup.css?ver=1.0cf7-cost-calculator/assets/admin/admin.css?ver=1.0cf7-cost-calculator/assets/admin/jquery.magnific-popup.min.js?ver=1.0cf7-cost-calculator/assets/admin/autosize.min.js?ver=1.0cf7-cost-calculator/assets/admin/admin.js?ver=1.0

HTML / DOM Fingerprints

CSS Classes
cf7cc-totalscf7-calculated-name
Data Attributes
data-formulas
JS Globals
cf7cc
REST Endpoints
/wp-json/contact-form-7/v1/contact-forms/
Shortcode Output
<span class="cf7cc-totals cf7-calculated-name"
FAQ

Frequently Asked Questions about Contact Form 7 Cost Calculator (Add-on for CF7)