
Contact Form 7 Cost Calculator (Add-on for CF7) Security & Risk Analysis
wordpress.org/plugins/cf7-cost-calculatorContact Form 7 Cost Calculator is a clean, simple quote / project price / estimation plugin which allows you to easily create price estimation contact …
Is Contact Form 7 Cost Calculator (Add-on for CF7) Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form 7 Cost Calculator (Add-on for CF7) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cf7-cost-calculator" v1.0.0 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerabilities or CVEs, suggesting a relatively stable and well-maintained code base in its history. There are also no reported issues with dangerous functions, file operations, external HTTP requests, or bundled libraries.
However, significant concerns arise from the static analysis. The plugin has a total of one entry point, an AJAX handler, which critically lacks any authentication or capability checks. This directly exposes a significant part of the plugin's functionality to unauthenticated users, creating a substantial attack surface. Furthermore, while the majority of output is properly escaped, a notable percentage (36%) is not, which could lead to Cross-Site Scripting (XSS) vulnerabilities if the unsanitized data originates from user input.
The lack of taint analysis results is neutral; it doesn't confirm safety but doesn't highlight specific flaws either. The absence of nonce checks on the identified AJAX handler is a critical oversight. In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the unprotected AJAX handler and potential for unescaped output present immediate and significant security risks that require urgent attention.
Key Concerns
- AJAX handler without authentication checks
- Significant portion of output not properly escaped
- Missing nonce checks on AJAX handler
Contact Form 7 Cost Calculator (Add-on for CF7) Security Vulnerabilities
Contact Form 7 Cost Calculator (Add-on for CF7) Code Analysis
Output Escaping
Contact Form 7 Cost Calculator (Add-on for CF7) Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Contact Form 7 Cost Calculator (Add-on for CF7) Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 Cost Calculator (Add-on for CF7) Alternatives
Cost Calculator for Contact Form 7 – Price Calculator Free
cf7-cost-calculator-price-calculation
With Contact Form 7 Cost Calculator – Price Calculation Form you can create forms with dynamically calculated fields to display the calculated values!
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 Cost Calculator (Add-on for CF7) Developer Profile
4 plugins · 140 total installs
How We Detect Contact Form 7 Cost Calculator (Add-on for CF7)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-cost-calculator/assets/admin/magnific-popup.css/wp-content/plugins/cf7-cost-calculator/assets/admin/admin.css/wp-content/plugins/cf7-cost-calculator/assets/admin/jquery.magnific-popup.min.js/wp-content/plugins/cf7-cost-calculator/assets/admin/autosize.min.js/wp-content/plugins/cf7-cost-calculator/assets/admin/admin.js/wp-content/plugins/cf7-cost-calculator/assets/admin/jquery.magnific-popup.min.js/wp-content/plugins/cf7-cost-calculator/assets/admin/autosize.min.js/wp-content/plugins/cf7-cost-calculator/assets/admin/admin.jscf7-cost-calculator/assets/admin/magnific-popup.css?ver=1.0cf7-cost-calculator/assets/admin/admin.css?ver=1.0cf7-cost-calculator/assets/admin/jquery.magnific-popup.min.js?ver=1.0cf7-cost-calculator/assets/admin/autosize.min.js?ver=1.0cf7-cost-calculator/assets/admin/admin.js?ver=1.0HTML / DOM Fingerprints
cf7cc-totalscf7-calculated-namedata-formulascf7cc/wp-json/contact-form-7/v1/contact-forms/<span class="cf7cc-totals cf7-calculated-name"