
Multi-Step for Contact Form 7 – Preview Submission Security & Risk Analysis
wordpress.org/plugins/cf7-multistepPlugin Provides step by step UI for Plugin Contact Form 7
Is Multi-Step for Contact Form 7 – Preview Submission Safe to Use in 2026?
Generally Safe
Score 100/100Multi-Step for Contact Form 7 – Preview Submission has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cf7-multistep" plugin v7.0.0 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, and unescaped output are significant strengths. The plugin also correctly utilizes prepared statements for all its SQL queries and properly escapes all output, indicating adherence to secure coding practices in these critical areas.
However, there are areas for improvement. The presence of two external HTTP requests, while not explicitly flagged as a vulnerability, represents a potential attack vector if the external services are compromised or if the plugin doesn't handle responses securely. Furthermore, the single AJAX handler, although protected by a nonce check, lacks a capability check. This means that while the AJAX request is protected against CSRF, any authenticated user could potentially trigger it, which could be a concern depending on the functionality of the AJAX handler.
The plugin's vulnerability history is exceptionally clean, with no recorded CVEs. This is a strong positive indicator, suggesting a history of secure development and maintenance. However, the lack of capability checks on the AJAX handler is a weakness that should be addressed to further harden the plugin's security, even in the absence of past vulnerabilities.
Key Concerns
- AJAX handler without capability check
- External HTTP requests present
Multi-Step for Contact Form 7 – Preview Submission Security Vulnerabilities
Multi-Step for Contact Form 7 – Preview Submission Release Timeline
Multi-Step for Contact Form 7 – Preview Submission Code Analysis
Output Escaping
Data Flow Analysis
Multi-Step for Contact Form 7 – Preview Submission Attack Surface
AJAX Handlers 1
WordPress Hooks 16
Maintenance & Trust
Multi-Step for Contact Form 7 – Preview Submission Maintenance & Trust
Maintenance Signals
Community Trust
Multi-Step for Contact Form 7 – Preview Submission Alternatives
Smart Grid-Layout Design for Contact Form 7
cf7-grid-layout
This plugins allow pure CSS responsive grid layouts for contact form 7. It enables rich interlinking of your CMS data via taxonomy/posts populated dr …
Multi Step for Contact Form 7
cf7-multi-step
Break your looooooong form into user-friendly steps
Multi Step Form Plugin
easy-multi-step-form
This plugin helps you to create multi step forms in wordpress using drag and drop builder and display anywhere in post/pages or in theme files using s …
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
metform
The most popular Elementor forms builder to create WordPress forms like contact forms, booking forms, feedback form, survey forms, application forms a …
Contact Form 7 Multi-Step Forms
contact-form-7-multi-step-module
Enables the Contact Form 7 plugin to create multi-page, multi-step forms.
Multi-Step for Contact Form 7 – Preview Submission Developer Profile
59 plugins · 26K total installs
How We Detect Multi-Step for Contact Form 7 – Preview Submission
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-multistep/backend/js/cf7-multistep.js/wp-content/plugins/cf7-multistep/backend/css/cf7-multistep.css/wp-content/plugins/cf7-multistep/backend/js/cf7-multistep.jscf7-multistep/backend/js/cf7-multistep.js?ver=cf7-multistep/backend/css/cf7-multistep.css?ver=HTML / DOM Fingerprints
multistep-formform-wrapnext-stepprev-stepmultistep-wrapmultistep-progressstepcurrent+2 more<!-- begin step --><!-- end step --><!-- begin step 2 --><!-- end step 2 -->+6 moredata-multistep-stepdata-multistep-form-iddata-multistep-progress-stepcf7_multistep_object