
WP contact form 7 db & Lead Manager plugin Security & Risk Analysis
wordpress.org/plugins/cf7-lead-managercontact form 7 db Storage & Lead Manager plugin allows you to save submission data from Contact Form 7 plugin.
Is WP contact form 7 db & Lead Manager plugin Safe to Use in 2026?
Generally Safe
Score 85/100WP contact form 7 db & Lead Manager plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cf7-lead-manager v1.0 plugin presents a mixed security posture. While the static analysis shows no direct attack surface in terms of exposed AJAX handlers, REST API routes, shortcodes, or cron events without authentication, significant concerns arise from the code's internal practices. The presence of the `unserialize` function, the complete absence of prepared statements for SQL queries, and the low rate of proper output escaping are substantial risks. Furthermore, the taint analysis indicates two high-severity flows with unsanitized paths, suggesting potential for data manipulation or injection vulnerabilities. The lack of nonce and capability checks across the board further exacerbates these risks, as it implies insufficient authorization and integrity protections. The plugin's vulnerability history is clean, which is a positive indicator, but it does not negate the inherent risks identified in the current codebase. In conclusion, despite a seemingly small attack surface, the internal coding practices, particularly the handling of potentially untrusted data via `unserialize`, unescaped output, and raw SQL queries, coupled with the high-severity taint flows, create a moderate to high-risk profile for this plugin.
Key Concerns
- Dangerous function: unserialize
- SQL queries without prepared statements
- Low percentage of properly escaped output
- High severity taint flows
- No nonce checks
- No capability checks
WP contact form 7 db & Lead Manager plugin Security Vulnerabilities
WP contact form 7 db & Lead Manager plugin Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP contact form 7 db & Lead Manager plugin Attack Surface
WordPress Hooks 7
Maintenance & Trust
WP contact form 7 db & Lead Manager plugin Maintenance & Trust
Maintenance Signals
Community Trust
WP contact form 7 db & Lead Manager plugin Alternatives
Contact Form Dashboard
contact-form-dashboard
CFD stores, organizes and presents all the submissions of the Contact Form 7 in a simplest way. It supports other interesting features like - Dashboard Analytics, Bulk emails / replies handling; Search, sort and export messages.
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Advanced Contact form 7 DB
advanced-cf7-db
Save all contact form 7 form submitted data to the database, View, Ordering, Change field labels and Import/Export data using CSV.
DM Contact Form 7 DB
dm-contact-form-7-db
Save Contact Form 7 entries.
WP Contact Form 7 DB Handler
wp-contact-form-7-db-handler
Store all your contact form 7 submission and easily access it. you can also filter and export it!
WP contact form 7 db & Lead Manager plugin Developer Profile
2 plugins · 20 total installs
How We Detect WP contact form 7 db & Lead Manager plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-lead-manager/css/style.css/wp-content/plugins/cf7-lead-manager/js/script.js/wp-content/plugins/cf7-lead-manager/js/script.jscf7-lead-manager/css/style.css?ver=cf7-lead-manager/js/script.js?ver=HTML / DOM Fingerprints
CF7LM-statsCF7LM-stats-widgetsetting cookies to store orinal HTTP_REFERER & LANDING PAGEthis information is retrieved later to add to databaseCreating and dropping tables for this plugin onPlugin activation and deactivation+2 moredata-cf7lm-urlCF7LM_visitor_information