
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Security & Risk Analysis
wordpress.org/plugins/cf7-mailchimpSend Contact Form 7, WPforms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to Mailchimp.
Is Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Safe to Use in 2026?
Generally Safe
Score 98/100Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms has a strong security track record. Known vulnerabilities have been patched promptly.
The 'cf7-mailchimp' v1.2.2 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of unprotected AJAX handlers, REST API routes, shortcodes, and cron events indicates a well-contained attack surface. The code also shows good practices in its use of prepared statements for SQL queries (76%) and proper output escaping (77%), along with a significant number of nonce and capability checks. This suggests a deliberate effort to implement security measures. However, a notable concern is the presence of a past medium-severity CVE related to Cross-Site Scripting. While this vulnerability is currently patched, its existence suggests that input validation and output sanitization may not have always been consistently robust, even with the otherwise positive code signals. The single file operation and two external HTTP requests, while not inherently insecure, represent potential vectors that warrant careful scrutiny in any deeper code review. The bundled Select2 library also presents a minor risk if it's not kept up-to-date, as outdated libraries can introduce vulnerabilities. Overall, the plugin appears to be developed with security in mind, but the historical vulnerability and potential for unaddressed weaknesses in file operations, external requests, and bundled libraries warrant a cautious approach.
Key Concerns
- Past medium severity CVE for XSS
- Bundled outdated library (Select2)
- 2 external HTTP requests
- 1 file operation
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.2.2 - Missing Authorization
CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Attack Surface
WordPress Hooks 39
Maintenance & Trust
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Maintenance & Trust
Maintenance Signals
Community Trust
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Alternatives
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Connect Contact Form 7 and Mailchimp
contact-form-7-mailchimp-extension
Connect Contact Form 7 to Mailchimp. Automatically sync form submissions to your Mailchimp audiences with merge field mapping, double opt-in, and opt- …
Contact Form user to Mailchimp Audience
contact-form-user-to-mailchimp-audience
Plugin sends Contact Form 7 (first name, last name, email, phone) to Mailchimp Audience.
reCaptcha Add-On for FormCraft
formcraft-recaptcha
Add reCaptcha to your FormCraft forms.
Contact Form 7 Connector
ari-cf7-connector
MailChimp, MailerLite and Zapier integration with Contact Form 7. Use form data smartly. Generate unlimited leads and extend mailing lists.
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms Developer Profile
32 plugins · 105K total installs
How We Detect Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-mailchimp/css/style.css/wp-content/plugins/cf7-mailchimp/js/admin.js/wp-content/plugins/cf7-mailchimp/js/frontend.js/wp-content/plugins/cf7-mailchimp/css/admin.css/wp-content/plugins/cf7-mailchimp/js/admin.js/wp-content/plugins/cf7-mailchimp/js/frontend.jscf7-mailchimp/css/style.css?ver=cf7-mailchimp/js/admin.js?ver=cf7-mailchimp/js/frontend.js?ver=cf7-mailchimp/css/admin.css?ver=HTML / DOM Fingerprints
vx_cf7_mailchimp_wrapcrmperks-noticesvxcf_mailchimp_menuvx_cf7_mailchimpdata-cf7-mailchimp-settingsvxcf_mailchimp_admin_objvx_cf7_mailchimp_vars/wp-json/cf7-mailchimp/v1/get_forms