
Data Source for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/cf7-data-sourceThe Data Source for Contact Form 7 plugin populates fields with data from external sources like databases, CSVs, URL parameters, ACF, and others.
Is Data Source for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100Data Source for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'cf7-data-source' plugin v1.8.6 demonstrates a generally good security posture with a commendable emphasis on secure coding practices. The static analysis reveals a robust implementation of security checks, with all identified entry points (AJAX handlers, shortcodes) appearing to have appropriate authentication and capability checks. Furthermore, the plugin exhibits strong output escaping (93%) and a significant majority of its SQL queries are properly prepared (64%), mitigating common injection risks. The absence of known CVEs and historical vulnerabilities further strengthens this positive assessment.
However, there are a few areas that warrant attention. The presence of one taint flow with unsanitized paths, even if not rated as critical or high, suggests a potential for vulnerabilities if user-supplied data is not handled meticulously in that specific flow. Additionally, while 64% of SQL queries are prepared, the remaining 36% that are not could still pose an SQL injection risk depending on the data they process. The plugin also performs two external HTTP requests and file operations, which are potential vectors for further attack if not secured against malicious inputs. The bundled Select2 library, if not actively maintained or kept up-to-date, could introduce vulnerabilities.
Key Concerns
- Taint flow with unsanitized paths found
- Some SQL queries not using prepared statements
- Performs external HTTP requests
- Performs file operations
- Bundled library (Select2) identified
Data Source for Contact Form 7 Security Vulnerabilities
Data Source for Contact Form 7 Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Data Source for Contact Form 7 Attack Surface
AJAX Handlers 1
Shortcodes 3
WordPress Hooks 34
Maintenance & Trust
Data Source for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Data Source for Contact Form 7 Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Advanced Contact form 7 DB
advanced-cf7-db
Save all contact form 7 form submitted data to the database, View, Ordering, Change field labels and Import/Export data using CSV.
Database for CF7
database-for-cf7
Save CF7 submitted form informations into your WordPress database.
WPSyncSheets For Contact Form 7 – CF7 Google Sheets Connector & Save to Database
contactsheets-lite
Connect Contact Form 7 submissions to Google Sheets to sync your form entries and save all cf7 forms submitted data to the database.
EP Exporter for Contact Form 7 (CF7)
ep-exporter-for-cf7
Smart and lightweight Contact Form 7 data exporter. Export your CF7 or CFDB7 submissions to CSV with advanced filtering options.
Data Source for Contact Form 7 Developer Profile
34 plugins · 89K total installs
How We Detect Data Source for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.