
Email addon for CF7 Security & Risk Analysis
wordpress.org/plugins/cf7-email-add-onEmail addon for CF7 plugin provides the responsive Email templates to admin and users.
Is Email addon for CF7 Safe to Use in 2026?
Generally Safe
Score 98/100Email addon for CF7 has a strong security track record. Known vulnerabilities have been patched promptly.
The "cf7-email-add-on" v2.0 plugin exhibits a generally good security posture, particularly in its handling of SQL queries and output escaping, which are almost entirely secure. The plugin also demonstrates a strong adherence to using prepared statements for its SQL queries and a very high percentage of properly escaped output, minimizing common web application vulnerabilities. The presence of nonce checks on its AJAX handlers further suggests an awareness of common WordPress security best practices, contributing to a reduced attack surface for these specific entry points.
However, a significant concern arises from the plugin's vulnerability history. It has a known high-severity CVE related to Improper Control of Filename for Include/Require Statements, which is a critical vulnerability type often associated with Remote File Inclusion (RFI) flaws. While this specific vulnerability is reported as patched, the presence of such a severe historical issue warrants continued vigilance and thorough testing for any residual or similar weaknesses. The static analysis did not reveal any direct critical or high severity taint flows, nor did it identify unprotected AJAX handlers or REST API routes, which is positive. Nevertheless, the historical RFI vulnerability suggests that past implementations may have had weaknesses that could reappear if not meticulously managed.
In conclusion, "cf7-email-add-on" v2.0 is a plugin with commendable secure coding practices regarding data handling and output sanitization. Its attack surface is relatively small, and its entry points are largely protected. The main area of caution stems from its past high-severity vulnerability, highlighting the importance of ongoing security audits and the need to ensure that all past security flaws are permanently remediated and not reintroduced in future versions. The lack of direct critical findings in the current static analysis is a positive sign, but the historical context necessitates a cautious approach.
Key Concerns
- Past high severity CVE (PHP RFI)
Email addon for CF7 Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Contact Form 7 Email Add on <= 1.9 - Authenticated (Contributor+) Local File Inclusion
Email addon for CF7 Code Analysis
Output Escaping
Email addon for CF7 Attack Surface
AJAX Handlers 2
WordPress Hooks 5
Maintenance & Trust
Email addon for CF7 Maintenance & Trust
Maintenance Signals
Community Trust
Email addon for CF7 Alternatives
Contact Form 7 Shortcode Enabler
contact-form-7-shortcode-enabler
This plugin enables the usage of external shortcodes inside Contact Form 7 Forms.
Elemailer Lite – Elementor email template & campaign builder
elemailer-lite
Elemailer is an Elementor addon to create Email templates. It gives you the most flexible design environment to design emails through drag and drop bu …
CF7 WOW Styler – Visual Styler for Contact Form 7 Forms
cf7-styler
Save time by styling Contact Form 7 once and applying the same design to multiple forms – CF7 WOW Styler keeps them on brand with visual controls and …
HTML Template for CF7
cf7-html-email-template-extension
Improve your Contact Form 7 emails with a HTML Template.
CF7 Views – Complete Entry Management for Contact Form 7
cf7-views
Easily display Contact Form 7 Entries/Submissions on your site frontend.
Email addon for CF7 Developer Profile
13 plugins · 17K total installs
How We Detect Email addon for CF7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-email-add-on/admin/assets/css/style.css/wp-content/plugins/cf7-email-add-on/admin/assets/js/custom.js/wp-content/plugins/cf7-email-add-on/admin/assets/js/custom.jscf7-email-add-on/admin/assets/css/style.css?ver=cf7-email-add-on/admin/assets/js/custom.js?ver=HTML / DOM Fingerprints
cf7-features-listcf7-buy-nowdata-plugin-urlcf7ea_ajax_object[fields][plugin_url]