Contact Form 7 OTP SMS Verification Security & Risk Analysis

wordpress.org/plugins/cf7-otp-sms-verification

SMS API: Buy Sms On All Bulk SMS

10 active installs v1.0.1 PHP + WP 3.8+ Updated Unknown
abl-otp-sms-verificationcontact-form-7-mobile-verificationcontact-form-7-otpotp-varification-in-contact-form-7
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form 7 OTP SMS Verification Safe to Use in 2026?

Generally Safe

Score 100/100

Contact Form 7 OTP SMS Verification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The cf7-otp-sms-verification v1.0.1 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, SQL queries without prepared statements, and properly escaped output are excellent indicators of secure coding practices. Furthermore, the lack of any recorded vulnerabilities, historical or recent, suggests a well-maintained and secure codebase. The plugin also demonstrates good practices by implementing nonce checks on its AJAX handlers and avoiding external HTTP requests that could be a vector for certain attacks. While the absence of capability checks on AJAX handlers is a minor concern, the overall security of the plugin appears robust. The limited attack surface, comprising only AJAX handlers, and the complete lack of critical or high-severity taint flows further reinforce this positive assessment.

Key Concerns

  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

Contact Form 7 OTP SMS Verification Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form 7 OTP SMS Verification Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
34 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped34 total outputs
Attack Surface

Contact Form 7 OTP SMS Verification Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_ihs_otp_ajax_hookcustom-functions.php:92
noprivwp_ajax_ihs_otp_ajax_hookcustom-functions.php:93
authwp_ajax_ihs_otp_reset_ajax_hookcustom-functions.php:193
noprivwp_ajax_ihs_otp_reset_ajax_hookcustom-functions.php:194
WordPress Hooks 4
actionwp_enqueue_scriptscustom-functions.php:46
actionadmin_enqueue_scriptscustom-functions.php:62
actionadmin_menuinc\admin-settings.php:8
actionadmin_initinc\admin-settings.php:20
Maintenance & Trust

Contact Form 7 OTP SMS Verification Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Contact Form 7 OTP SMS Verification Alternatives

No alternatives data available yet.

Developer Profile

Contact Form 7 OTP SMS Verification Developer Profile

WIT Solution

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 OTP SMS Verification

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-otp-sms-verification/style.css/wp-content/plugins/cf7-otp-sms-verification/vendor/js/alert.js/wp-content/plugins/cf7-otp-sms-verification/vendor/js/main.js/wp-content/plugins/cf7-otp-sms-verification/vendor/js/reset-password.js/wp-content/plugins/cf7-otp-sms-verification/css/admin.css/wp-content/plugins/cf7-otp-sms-verification/vendor/js/admin.js
Script Paths
/wp-content/plugins/cf7-otp-sms-verification/vendor/js/alert.js/wp-content/plugins/cf7-otp-sms-verification/vendor/js/main.js/wp-content/plugins/cf7-otp-sms-verification/vendor/js/reset-password.js/wp-content/plugins/cf7-otp-sms-verification/vendor/js/admin.js

HTML / DOM Fingerprints

Data Attributes
form_selectorsubmit_btn_selectorinput_requiredmobile_input_namecountry_codeihs_otp_form_selector+8 more
JS Globals
otp_objreset_pass_obj
REST Endpoints
/wp-json/ihs_otp_ajax_hook/wp-json/ihs_otp_reset_ajax_hook
FAQ

Frequently Asked Questions about Contact Form 7 OTP SMS Verification