HTML Template for CF7 Security & Risk Analysis

wordpress.org/plugins/cf7-html-email-template-extension

Improve your Contact Form 7 emails with a HTML Template.

1K active installs v2.2.2 PHP 7.4+ WP 4.5+ Updated Nov 3, 2025
cf7contact-formcontact-form-7email-templateemails
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is HTML Template for CF7 Safe to Use in 2026?

Generally Safe

Score 100/100

HTML Template for CF7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The plugin "cf7-html-email-template-extension" v2.2.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the analysis indicates no dangerous functions, zero total SQL queries with 100% using prepared statements, and no external HTTP requests, all of which are positive indicators. The plugin also reports no known CVEs and no recorded vulnerabilities in its history, suggesting a well-maintained and secure codebase. However, a notable area for improvement is the output escaping, where only 61% of outputs are properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if untrusted data is rendered without adequate sanitization. While the taint analysis shows no unsanitized paths, the existing unescaped outputs represent a latent risk. The presence of one file operation, while not inherently risky, warrants attention to ensure it's handled securely and doesn't involve user-supplied input.

Key Concerns

  • Low output escaping rate
  • One file operation detected
Vulnerabilities
None known

HTML Template for CF7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

HTML Template for CF7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
11 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

61% escaped18 total outputs
Attack Surface

HTML Template for CF7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionplugins_loadedcf7-html-email-template-extension.php:110
actionplugins_loadedcf7-html-email-template-extension.php:356
filtercf7hete_disable_ace_editorincludes\backward-compatibility.php:13
actionadmin_initmodules\cf7\class-module-cf7.php:50
actionadmin_enqueue_scriptsmodules\cf7\class-module-cf7.php:51
actionwpcf7_save_contact_formmodules\cf7\class-module-cf7.php:52
actionwpcf7_admin_misc_pub_sectionmodules\cf7\class-module-cf7.php:53
filterwpcf7_editor_panelsmodules\cf7\class-module-cf7.php:55
filterwpcf7_contact_form_propertiesmodules\cf7\class-module-cf7.php:56
filterwpcf7_pre_construct_contact_form_propertiesmodules\cf7\class-module-cf7.php:57
filterwpcf7_mail_componentsmodules\cf7\class-module-cf7.php:58
actionadmin_noticesmodules\dependence\class-module-dependence.php:69
Maintenance & Trust

HTML Template for CF7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 3, 2025
PHP min version7.4
Downloads28K

Community Trust

Rating94/100
Number of ratings3
Active installs1K
Developer Profile

HTML Template for CF7 Developer Profile

Mário Valney

7 plugins · 34K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
847 days
View full developer profile
Detection Fingerprints

How We Detect HTML Template for CF7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-html-email-template-extension/modules/core/cf7-html-email-template-extension-core.php/wp-content/plugins/cf7-html-email-template-extension/modules/css-class/css-class.php/wp-content/plugins/cf7-html-email-template-extension/modules/css-class/css-class-main.js/wp-content/plugins/cf7-html-email-template-extension/modules/css-class/css-class.css/wp-content/plugins/cf7-html-email-template-extension/modules/fields-template/fields-template.php/wp-content/plugins/cf7-html-email-template-extension/modules/fields-template/fields-template-main.js/wp-content/plugins/cf7-html-email-template-extension/modules/fields-template/fields-template.css/wp-content/plugins/cf7-html-email-template-extension/modules/fields-template/views/fields-template.php+8 more
Script Paths
/wp-content/plugins/cf7-html-email-template-extension/modules/css-class/css-class-main.js/wp-content/plugins/cf7-html-email-template-extension/modules/fields-template/fields-template-main.js/wp-content/plugins/cf7-html-email-template-extension/modules/pdf-attachment/pdf-attachment-main.js/wp-content/plugins/cf7-html-email-template-extension/modules/styles/styles-main.js
Version Parameters
cf7-html-email-template-extension/modules/css-class/css-class.css?ver=cf7-html-email-template-extension/modules/css-class/css-class-main.js?ver=cf7-html-email-template-extension/modules/fields-template/fields-template.css?ver=cf7-html-email-template-extension/modules/fields-template/fields-template-main.js?ver=cf7-html-email-template-extension/modules/pdf-attachment/pdf-attachment.css?ver=cf7-html-email-template-extension/modules/pdf-attachment/pdf-attachment-main.js?ver=cf7-html-email-template-extension/modules/styles/styles.css?ver=cf7-html-email-template-extension/modules/styles/styles-main.js?ver=

HTML / DOM Fingerprints

CSS Classes
cf7-html-email-template-extension-css-classcf7-html-email-template-extension-fields-templatecf7-html-email-template-extension-pdf-attachmentcf7-html-email-template-extension-styles
JS Globals
cf7hete_css_class_paramscf7hete_fields_template_paramscf7hete_pdf_attachment_paramscf7hete_styles_params
FAQ

Frequently Asked Questions about HTML Template for CF7