
Nonaki – Contact Form 7 email template customizer Security & Risk Analysis
wordpress.org/plugins/cf7-email-template-builderDrag and Drop Email Template builder for Contact form 7
Is Nonaki – Contact Form 7 email template customizer Safe to Use in 2026?
Generally Safe
Score 85/100Nonaki – Contact Form 7 email template customizer has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "cf7-email-template-builder" v1.0.0 plugin exhibits a strong security posture. The absence of any identified dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and a complete lack of file operations or external HTTP requests are significant strengths. Furthermore, all identified outputs are properly escaped, mitigating the risk of cross-site scripting vulnerabilities. The plugin also has no recorded vulnerability history, suggesting a history of secure development.
However, the analysis does highlight a concerning lack of security best practices related to entry points and authorization. The plugin has zero identified entry points (AJAX handlers, REST API routes, shortcodes, cron events), which is unusual and could indicate that either the plugin is purely passive or that its entry points are not being effectively discovered by the analysis tool. More critically, there are zero capability checks and zero nonce checks. This implies that even if entry points were present, they might not be adequately protected against unauthorized access or manipulation, leaving them vulnerable if any unexpected entry points are discovered or if the analysis missed something.
In conclusion, while the plugin's code itself appears to be free from common vulnerabilities like SQL injection and XSS, the significant gaps in authorization checks represent a latent risk. The lack of identified entry points is also an anomaly that warrants further investigation. The plugin demonstrates good practices in code execution and output handling but falls short in securing its potential interaction points with the WordPress environment. Therefore, the overall risk is low due to the absence of known exploits and secure coding in core areas, but a moderate risk exists due to the potential for unauthorized access if any entry points exist and are unprotected.
Key Concerns
- No capability checks implemented
- No nonce checks implemented
Nonaki – Contact Form 7 email template customizer Security Vulnerabilities
Nonaki – Contact Form 7 email template customizer Release Timeline
Nonaki – Contact Form 7 email template customizer Code Analysis
Output Escaping
Nonaki – Contact Form 7 email template customizer Attack Surface
WordPress Hooks 11
Maintenance & Trust
Nonaki – Contact Form 7 email template customizer Maintenance & Trust
Maintenance Signals
Community Trust
Nonaki – Contact Form 7 email template customizer Alternatives
EmailKit – Email Customizer for WooCommerce & WP
emailkit
EmailKit is a powerful WordPress and WooCommerce email customizer tool, free for everyone! It allows users to customize and design templates that show …
YayMail – WooCommerce Email Customizer
yaymail
Customize WooCommerce email templates with an advanced drag-and-drop email builder. Works great with 80+ WooCommerce Email Customizer Addons.
Elemailer Lite – Elementor email template & campaign builder
elemailer-lite
Elemailer is an Elementor addon to create Email templates. It gives you the most flexible design environment to design emails through drag and drop bu …
Email addon for CF7
cf7-email-add-on
Email addon for CF7 plugin provides the responsive Email templates to admin and users.
HTML Template for CF7
cf7-html-email-template-extension
Improve your Contact Form 7 emails with a HTML Template.
Nonaki – Contact Form 7 email template customizer Developer Profile
4 plugins · 50 total installs
How We Detect Nonaki – Contact Form 7 email template customizer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-email-template-builder/assets/js/app.js/wp-content/plugins/cf7-email-template-builder/assets/js/vendor.jsHTML / DOM Fingerprints
blockManager.add('cf7-category: 'Contact Form 7',nonaki.BlockManager