Integrate Contact Form 7 and iContact Security & Risk Analysis

wordpress.org/plugins/cf7-icontact-extension

Connect Contact Form 7 to iContact. Automatically add form submissions to your iContact mailing lists.

40 active installs v026.02.10.1909 PHP 7.4+ WP 6.2+ Updated Mar 2, 2026
contact-formform-integrationicontactmailing-listnewsletter
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Integrate Contact Form 7 and iContact Safe to Use in 2026?

Generally Safe

Score 100/100

Integrate Contact Form 7 and iContact has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "cf7-icontact-extension" v026.02.10.1909 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The plugin demonstrates excellent practices in output escaping, with all identified outputs being properly sanitized. It also shows a commendable approach to SQL queries, with a high percentage utilizing prepared statements, significantly reducing the risk of SQL injection vulnerabilities. Furthermore, the absence of any recorded CVEs or known vulnerabilities in its history suggests a mature and well-maintained codebase regarding external security threats.

However, the analysis does highlight a few areas that warrant attention. The most significant concern is the complete lack of nonce checks across all entry points, including AJAX handlers and shortcodes. This absence creates a substantial risk for Cross-Site Request Forgery (CSRF) attacks, as unauthorized actions could be performed if an attacker can trick a logged-in user into triggering these actions. Additionally, while the plugin has capability checks, their presence is limited, and the security of cron events could be further strengthened by ensuring appropriate checks are in place. The external HTTP requests, while not inherently a vulnerability, represent potential points of failure or attack vectors if the external services are compromised or introduce malicious content.

In conclusion, the plugin benefits from robust code sanitization and a clean vulnerability history. The developer's commitment to secure coding practices for output and database interactions is evident. The primary weakness lies in the lack of CSRF protection mechanisms. Addressing the nonce check deficiency is crucial to enhance the plugin's overall security and mitigate potential exploitation.

Key Concerns

  • Missing nonce checks on all entry points
  • Limited capability checks
Vulnerabilities
None known

Integrate Contact Form 7 and iContact Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Integrate Contact Form 7 and iContact Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
3 prepared
Unescaped Output
0
119 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
6
Bundled Libraries
0

SQL Query Safety

75% prepared4 total queries

Output Escaping

100% escaped119 total outputs
Attack Surface

Integrate Contact Form 7 and iContact Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionadmin_print_scriptsincludes\admin\class-icf7ic-admin-assets.php:40
filteradmin_body_classincludes\admin\class-icf7ic-admin-assets.php:41
actionadmin_bar_menuincludes\admin\class-icf7ic-admin-bar.php:37
actionwp_enqueue_scriptsincludes\admin\class-icf7ic-admin-bar.php:38
actionadmin_enqueue_scriptsincludes\admin\class-icf7ic-admin-bar.php:39
actionadmin_footerincludes\admin\class-icf7ic-admin-bar.php:40
actionwp_footerincludes\admin\class-icf7ic-admin-bar.php:41
filterwpcf7_editor_panelsincludes\admin\class-icf7ic-admin-panel.php:24
actionwpcf7_after_saveincludes\admin\class-icf7ic-admin-panel.php:25
actionadmin_noticesincludes\class-icf7ic-bootstrap.php:38
filterauto_update_pluginincludes\core\class-icf7ic-wordpress.php:24
actionrest_api_initincludes\rest\class-icf7ic-rest-controller.php:97
actionwpcf7_mail_sentincludes\services\class-icf7ic-subscriber.php:24
filtercron_schedulesincludes\signals\class-icf7ic-signals-scheduler.php:108
actionicf7ic_metrics_heartbeatincludes\signals\class-icf7ic-signals-scheduler.php:109
actionadmin_initincludes\signals\class-icf7ic-signals-scheduler.php:110
actionicf7ic_subscription_successincludes\signals\class-icf7ic-signals-scheduler.php:113
actionicf7ic_on_activationincludes\signals\class-icf7ic-signals-tracker.php:60
actionicf7ic_on_deactivationincludes\signals\class-icf7ic-signals-tracker.php:61
actionplugins_loadedintegrate-cf7-and-ic.php:30

Scheduled Events 13

icf7ic_metrics_heartbeat
icf7ic_metrics_heartbeat
icf7ic_metrics_heartbeat
icf7ic_metrics_heartbeat
icf7ic_metrics_heartbeat
icf7ic_metrics_heartbeat
icf7ic_metrics_heartbeat
icf7ic_metrics_heartbeat
icf7ic_metrics_heartbeat
icf7ic_metrics_heartbeat
icf7ic_metrics_heartbeat
icf7ic_metrics_heartbeat
icf7ic_metrics_heartbeat
Maintenance & Trust

Integrate Contact Form 7 and iContact Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 2, 2026
PHP min version7.4
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Integrate Contact Form 7 and iContact Developer Profile

Renzo Johnson

5 plugins · 51K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
346 days
View full developer profile
Detection Fingerprints

How We Detect Integrate Contact Form 7 and iContact

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-icontact-extension/assets/css/admin.css/wp-content/plugins/cf7-icontact-extension/assets/js/admin.js
Script Paths
/wp-content/plugins/cf7-icontact-extension/assets/js/admin.js
Version Parameters
cf7-icontact-extension/assets/css/admin.css?ver=cf7-icontact-extension/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
icf7ic-lite
Data Attributes
data-iddata-action
JS Globals
icf7ic
REST Endpoints
/wp-json/icf7ic/v1/
FAQ

Frequently Asked Questions about Integrate Contact Form 7 and iContact