Email addon for CF7 Security & Risk Analysis

wordpress.org/plugins/cf7-email-add-on

Email addon for CF7 plugin provides the responsive Email templates to admin and users.

3K active installs v2.0 PHP 7.4+ WP 6.6+ Updated Sep 26, 2025
cf7contactform7email-templatehtml-emailshortcode
98
A · Safe
CVEs total1
Unpatched0
Last CVENov 20, 2024
Safety Verdict

Is Email addon for CF7 Safe to Use in 2026?

Generally Safe

Score 98/100

Email addon for CF7 has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 20, 2024Updated 6mo ago
Risk Assessment

The "cf7-email-add-on" v2.0 plugin exhibits a generally good security posture, particularly in its handling of SQL queries and output escaping, which are almost entirely secure. The plugin also demonstrates a strong adherence to using prepared statements for its SQL queries and a very high percentage of properly escaped output, minimizing common web application vulnerabilities. The presence of nonce checks on its AJAX handlers further suggests an awareness of common WordPress security best practices, contributing to a reduced attack surface for these specific entry points.

However, a significant concern arises from the plugin's vulnerability history. It has a known high-severity CVE related to Improper Control of Filename for Include/Require Statements, which is a critical vulnerability type often associated with Remote File Inclusion (RFI) flaws. While this specific vulnerability is reported as patched, the presence of such a severe historical issue warrants continued vigilance and thorough testing for any residual or similar weaknesses. The static analysis did not reveal any direct critical or high severity taint flows, nor did it identify unprotected AJAX handlers or REST API routes, which is positive. Nevertheless, the historical RFI vulnerability suggests that past implementations may have had weaknesses that could reappear if not meticulously managed.

In conclusion, "cf7-email-add-on" v2.0 is a plugin with commendable secure coding practices regarding data handling and output sanitization. Its attack surface is relatively small, and its entry points are largely protected. The main area of caution stems from its past high-severity vulnerability, highlighting the importance of ongoing security audits and the need to ensure that all past security flaws are permanently remediated and not reintroduced in future versions. The lack of direct critical findings in the current static analysis is a positive sign, but the historical context necessitates a cautious approach.

Key Concerns

  • Past high severity CVE (PHP RFI)
Vulnerabilities
1

Email addon for CF7 Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-10898high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Contact Form 7 Email Add on <= 1.9 - Authenticated (Contributor+) Local File Inclusion

Nov 20, 2024 Patched in 2.0 (174d)
Code Analysis
Analyzed Mar 16, 2026

Email addon for CF7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
141 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped142 total outputs
Attack Surface

Email addon for CF7 Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_cf7_email_add_on_add_admin_templateinclude\class-cf7-email.php:37
noprivwp_ajax_cf7_email_add_on_add_admin_templateinclude\class-cf7-email.php:38
WordPress Hooks 5
actionplugins_loadedcontact-form-7-email-add-on.php:81
filterplugin_row_metainclude\class-cf7-email.php:30
filterwpcf7_editor_panelsinclude\class-cf7-email.php:40
actionadmin_enqueue_scriptsinclude\class-cf7-email.php:42
actionwpcf7_save_contact_forminclude\class-cf7-email.php:44
Maintenance & Trust

Email addon for CF7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 26, 2025
PHP min version7.4
Downloads37K

Community Trust

Rating92/100
Number of ratings9
Active installs3K
Developer Profile

Email addon for CF7 Developer Profile

KrishaWeb

13 plugins · 17K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
655 days
View full developer profile
Detection Fingerprints

How We Detect Email addon for CF7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-email-add-on/admin/assets/css/style.css/wp-content/plugins/cf7-email-add-on/admin/assets/js/custom.js
Script Paths
/wp-content/plugins/cf7-email-add-on/admin/assets/js/custom.js
Version Parameters
cf7-email-add-on/admin/assets/css/style.css?ver=cf7-email-add-on/admin/assets/js/custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
cf7-features-listcf7-buy-now
Data Attributes
data-plugin-url
JS Globals
cf7ea_ajax_object
Shortcode Output
[fields][plugin_url]
FAQ

Frequently Asked Questions about Email addon for CF7