
CF7 HubSpot Forms Add-on For Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/cf7-hubspot-forms-add-on-for-contact-form-7This plugin integrates HubSpot forms with Contact Form 7 forms.
Is CF7 HubSpot Forms Add-on For Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100CF7 HubSpot Forms Add-on For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin exhibits a mixed security posture. On one hand, it demonstrates good practices by exclusively using prepared statements for SQL queries and avoiding bundled libraries, which can be sources of vulnerabilities. The absence of any recorded CVEs further suggests a generally stable security history. However, significant concerns arise from the static analysis. The presence of the `unserialize` function is a critical risk, as it can lead to Remote Code Execution (RCE) if processing untrusted data. Furthermore, the taint analysis reveals two high-severity flows with unsanitized paths, indicating potential for data injection or manipulation vulnerabilities. The complete lack of capability checks and nonce checks on entry points, combined with the absence of any exposed AJAX handlers or REST API routes that would typically require these, raises questions about the plugin's overall security implementation and its reliance on other components for authorization, or potentially an oversight in the analysis scope. Despite its clean vulnerability history, the identified code signals and taint analysis necessitate caution.
Key Concerns
- Dangerous function "unserialize" found
- High severity taint flow with unsanitized path
- High severity taint flow with unsanitized path
- Capability checks missing
- Nonce checks missing
- Output escaping not fully implemented (1/3)
CF7 HubSpot Forms Add-on For Contact Form 7 Security Vulnerabilities
CF7 HubSpot Forms Add-on For Contact Form 7 Release Timeline
CF7 HubSpot Forms Add-on For Contact Form 7 Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
CF7 HubSpot Forms Add-on For Contact Form 7 Attack Surface
WordPress Hooks 4
Maintenance & Trust
CF7 HubSpot Forms Add-on For Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
CF7 HubSpot Forms Add-on For Contact Form 7 Alternatives
WPOP Contact Form 7 to Hubspot
wpop-contactform-hubspot
Add Contact Form 7 Data to Hubspot Contact lists.
Contact Form user to HubSpot Contacts
cf7-user-to-hubspot-contacts
Plugin sends Contact Form 7 (first name, last name, email, phone) to HubSpot CRM contact.
MWB CF7 Integration with HubSpot -Sync HubSpot Forms, Contacts, Tickets
mwb-cf7-integration-with-hubspot
Automate lead generation & nurturing by syncing Contact Form 7 data over HubSpot with this MWB CF7 Integration with HubSpot plugin.
Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-hubspot
Send Contact Form 7, WPForms, Elementor, Ninja Forms, WPforms, Elementor, Ninja Forms, Contact Form Entries Plugin and many other contact form submiss …
Connect CF7 to HubSpot
connect-cf7-to-hubspot
Seamlessly Connect CF7 to HubSpot to automate your lead management process.
CF7 HubSpot Forms Add-on For Contact Form 7 Developer Profile
3 plugins · 310 total installs
How We Detect CF7 HubSpot Forms Add-on For Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-hubspot-forms-add-on-for-contact-form-7/assets/css/styles.css/wp-content/plugins/cf7-hubspot-forms-add-on-for-contact-form-7/assets/js/scripts.js/wp-content/plugins/cf7-hubspot-forms-add-on-for-contact-form-7/assets/js/scripts.jscf7-hubspot-forms-add-on-for-contact-form-7/assets/css/styles.css?ver=cf7-hubspot-forms-add-on-for-contact-form-7/assets/js/scripts.js?ver=HTML / DOM Fingerprints
add_fieldremove_fieldcf7hsfi_enabledcf7hsfi_portal_idcf7hsfi_form_idcf7hsfi_form_page_urlcf7hsfi_form_page_namecf7hsfi_cf7_field+1 more