Custom Spinner for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/cf7-custom-spinner

Customize the spinning Loader Animation of Contact Form 7

1K active installs v2.0.3 PHP 5.4+ WP 4.0+ Updated Apr 16, 2024
cf7contact-formcontact-form-7custom-formspinner
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Custom Spinner for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 92/100

Custom Spinner for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "cf7-custom-spinner" v2.0.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, all SQL queries are properly prepared, and there are no known vulnerabilities (CVEs) or recorded past vulnerabilities. The absence of external HTTP requests and bundled libraries is also a positive indicator. However, a significant concern arises from the output escaping analysis, where 0% of the 17 total outputs are properly escaped. This suggests a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied data could be rendered directly in the browser without proper sanitization.

While the static analysis reports a clean slate regarding taint flows and a protected attack surface (0 unprotected entry points), the lack of output escaping is a critical oversight that exposes users to risk. The single nonce check and the absence of capability checks, when combined with the unescaped outputs, could potentially allow unauthorized modification of plugin behavior or data if an attacker can inject malicious scripts through the unescaped output points. The vulnerability history being completely clean is encouraging but doesn't mitigate the immediate risks identified in the static analysis.

Key Concerns

  • 100% of outputs are not properly escaped
  • 0% capability checks on entry points
Vulnerabilities
None known

Custom Spinner for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Spinner for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped17 total outputs
Attack Surface

Custom Spinner for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitinc\class-cf7-custom-spinner-admin.php:134
actionadmin_initinc\class-cf7-custom-spinner-admin.php:135
actionadmin_enqueue_scriptsinc\class-cf7-custom-spinner-admin.php:136
actionadmin_enqueue_scriptsinc\class-cf7-custom-spinner-admin.php:137
actionadmin_footerinc\class-cf7-custom-spinner-admin.php:138
actionadmin_footerinc\class-cf7-custom-spinner-admin.php:139
actionadmin_menuinc\class-cf7-custom-spinner-admin.php:140
actionwp_enqueue_scriptsinc\class-cf7-custom-spinner-frontend.php:52
Maintenance & Trust

Custom Spinner for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.8
Last updatedApr 16, 2024
PHP min version5.4
Downloads15K

Community Trust

Rating80/100
Number of ratings11
Active installs1K
Developer Profile

Custom Spinner for Contact Form 7 Developer Profile

Peter Raschendorfer

7 plugins · 13K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Spinner for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-custom-spinner/css/cf7-custom-spinner.css/wp-content/plugins/cf7-custom-spinner/js/cf7-custom-spinner.js
Version Parameters
/wp-content/plugins/cf7-custom-spinner/css/cf7-custom-spinner.css?ver=/wp-content/plugins/cf7-custom-spinner/js/cf7-custom-spinner.js?ver=

HTML / DOM Fingerprints

CSS Classes
cf7-custom-spinner-wrapcf7-custom-spinner-overlaycf7-custom-spinner-wrappercf7-custom-spinner-contentcf7-custom-spinner-loading
HTML Comments
<!-- CF7 Custom Spinner Loader --><!-- CF7 Custom Spinner Overlay --><!-- CF7 Custom Spinner Wrapper --><!-- CF7 Custom Spinner Content -->
Data Attributes
data-cf7-custom-spinner-typedata-cf7-custom-spinner-colordata-cf7-custom-spinner-size
JS Globals
cf7_custom_spinner_settings
FAQ

Frequently Asked Questions about Custom Spinner for Contact Form 7