CF7 HubSpot Forms Add-on For Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/cf7-hubspot-forms-add-on-for-contact-form-7

This plugin integrates HubSpot forms with Contact Form 7 forms.

300 active installs v1.0 PHP + WP 3.0.1+ Updated Aug 21, 2016
contact-form-7hubspothubspot-formshubspot-forms-apihubspot-forms-api-integration
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CF7 HubSpot Forms Add-on For Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

CF7 HubSpot Forms Add-on For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The plugin exhibits a mixed security posture. On one hand, it demonstrates good practices by exclusively using prepared statements for SQL queries and avoiding bundled libraries, which can be sources of vulnerabilities. The absence of any recorded CVEs further suggests a generally stable security history. However, significant concerns arise from the static analysis. The presence of the `unserialize` function is a critical risk, as it can lead to Remote Code Execution (RCE) if processing untrusted data. Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths, indicating potential for data injection or manipulation vulnerabilities. The complete lack of capability checks and nonce checks on entry points, combined with the absence of any exposed AJAX handlers or REST API routes that would typically require these, raises questions about the plugin's overall security implementation and its reliance on other components for authorization, or potentially an oversight in the analysis scope. Despite its clean vulnerability history, the identified code signals and taint analysis necessitate caution.

Key Concerns

  • Dangerous function "unserialize" found
  • High severity taint flow with unsanitized path
  • High severity taint flow with unsanitized path
  • Capability checks missing
  • Nonce checks missing
  • Output escaping not fully implemented (1/3)
Vulnerabilities
None known

CF7 HubSpot Forms Add-on For Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CF7 HubSpot Forms Add-on For Contact Form 7 Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

CF7 HubSpot Forms Add-on For Contact Form 7 Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
0 prepared
Unescaped Output
1
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Dangerous Functions Found

unserialize$form_fields = $form_fields_str ? unserialize($form_fields_str) : false;cf7-hubspot-forms-addon.php:81
unserialize$debug_log = unserialize($debug_log);cf7-hubspot-forms-addon.php:130
unserialize$form_fields = $form_fields_str ? unserialize($form_fields_str) : false;cf7-hubspot-forms-addon.php:211

Output Escaping

67% escaped3 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
cf7hsfi_admin_panel_content (cf7-hubspot-forms-addon.php:71)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CF7 HubSpot Forms Add-on For Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_enqueue_scriptscf7-hubspot-forms-addon.php:53
filterwpcf7_editor_panelscf7-hubspot-forms-addon.php:69
actionwpcf7_save_contact_formcf7-hubspot-forms-addon.php:200
actionwpcf7_before_send_mailcf7-hubspot-forms-addon.php:267
Maintenance & Trust

CF7 HubSpot Forms Add-on For Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedAug 21, 2016
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings4
Active installs300
Developer Profile

CF7 HubSpot Forms Add-on For Contact Form 7 Developer Profile

Ahmad Karim

3 plugins · 310 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CF7 HubSpot Forms Add-on For Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-hubspot-forms-add-on-for-contact-form-7/assets/css/styles.css/wp-content/plugins/cf7-hubspot-forms-add-on-for-contact-form-7/assets/js/scripts.js
Script Paths
/wp-content/plugins/cf7-hubspot-forms-add-on-for-contact-form-7/assets/js/scripts.js
Version Parameters
cf7-hubspot-forms-add-on-for-contact-form-7/assets/css/styles.css?ver=cf7-hubspot-forms-add-on-for-contact-form-7/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
add_fieldremove_field
Data Attributes
cf7hsfi_enabledcf7hsfi_portal_idcf7hsfi_form_idcf7hsfi_form_page_urlcf7hsfi_form_page_namecf7hsfi_cf7_field+1 more
FAQ

Frequently Asked Questions about CF7 HubSpot Forms Add-on For Contact Form 7