
Multi Step for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/cf7-multi-stepBreak your looooooong form into user-friendly steps
Is Multi Step for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 98/100Multi Step for Contact Form 7 has a strong security track record. Known vulnerabilities have been patched promptly.
The cf7-multi-step plugin v2.7.9 presents a moderate security risk. While it demonstrates some good security practices, such as a majority of SQL queries using prepared statements and the presence of nonce and capability checks, there are significant concerns. The plugin has a small but unprotected attack surface, with two entry points (AJAX and REST API routes) lacking proper authentication or permission checks. Furthermore, a notable portion of output escaping is not properly handled, potentially leading to cross-site scripting vulnerabilities. The plugin's vulnerability history reveals a past high-severity SQL injection vulnerability, and though it's currently patched, this pattern indicates a potential for recurring issues if development practices are not robust. The lack of taint analysis data is a weakness, as it prevents a deeper understanding of data flow vulnerabilities. Overall, while the plugin has some strengths, the unprotected entry points and historical vulnerability suggest a need for increased security scrutiny and development diligence.
Key Concerns
- Unprotected AJAX handler
- Unprotected REST API route
- Low percentage of properly escaped output
- Past high-severity SQL injection vulnerability
Multi Step for Contact Form 7 Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Multi Step for Contact Form <= 2.7.7 - Unauthenticated SQL Injection
Multi Step for Contact Form 7 Code Analysis
SQL Query Safety
Output Escaping
Multi Step for Contact Form 7 Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 24
Maintenance & Trust
Multi Step for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Multi Step for Contact Form 7 Alternatives
Smart Grid-Layout Design for Contact Form 7
cf7-grid-layout
This plugins allow pure CSS responsive grid layouts for contact form 7. It enables rich interlinking of your CMS data via taxonomy/posts populated dr …
Multi Step Form
multi-step-form
Guide your customers with the animated progress bar. Generate dynamic multi step forms. Divide longer forms into small steps for better usability.
NEX-Forms – Ultimate Forms Plugin for WordPress
nex-forms-express-wp-form-builder
Build beautiful responsive forms for WordPress. Contact forms, surveys, quizzes, booking forms, payments, popups & more with NEX-Forms...
NEX-Forms ADD ON – Form Themes
nex-forms-form-themes-add-on
Build beautiful responsive forms for WordPress. Contact forms, surveys, quizzes, booking forms, payments, popups & more with NEX-Forms...
NEX-Forms ADD ON – Zapier Integration
nex-forms-zapier-add-on
The NEX-Forms Zapier Integration Add-on enables you to seamlessly connect your form submissions to over 10,000 apps.
Multi Step for Contact Form 7 Developer Profile
13 plugins · 496K total installs
How We Detect Multi Step for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-multi-step/assets/admin/css/admin-dashboard.csscf7-multi-step/assets/admin/css/admin-dashboard.css?ver=HTML / DOM Fingerprints
cf7ms-wrap-postboxcf7mls-postbox-title-wrapcf7mls-postbox-list-wrapcf7mls-list-checkedcf7mls-postbox-img-wrapdata-cf7mls-stepcf7mls_script_vars<div class="cf7mls-steps">