
Contact Form 7 OTP SMS Verification Security & Risk Analysis
wordpress.org/plugins/cf7-otp-sms-verificationSMS API: Buy Sms On All Bulk SMS
Is Contact Form 7 OTP SMS Verification Safe to Use in 2026?
Generally Safe
Score 100/100Contact Form 7 OTP SMS Verification has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The cf7-otp-sms-verification v1.0.1 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, SQL queries without prepared statements, and properly escaped output are excellent indicators of secure coding practices. Furthermore, the lack of any recorded vulnerabilities, historical or recent, suggests a well-maintained and secure codebase. The plugin also demonstrates good practices by implementing nonce checks on its AJAX handlers and avoiding external HTTP requests that could be a vector for certain attacks. While the absence of capability checks on AJAX handlers is a minor concern, the overall security of the plugin appears robust. The limited attack surface, comprising only AJAX handlers, and the complete lack of critical or high-severity taint flows further reinforce this positive assessment.
Key Concerns
- Missing capability checks on AJAX handlers
Contact Form 7 OTP SMS Verification Security Vulnerabilities
Contact Form 7 OTP SMS Verification Code Analysis
Output Escaping
Contact Form 7 OTP SMS Verification Attack Surface
AJAX Handlers 4
WordPress Hooks 4
Maintenance & Trust
Contact Form 7 OTP SMS Verification Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 OTP SMS Verification Alternatives
No alternatives data available yet.
Contact Form 7 OTP SMS Verification Developer Profile
1 plugin · 10 total installs
How We Detect Contact Form 7 OTP SMS Verification
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-otp-sms-verification/style.css/wp-content/plugins/cf7-otp-sms-verification/vendor/js/alert.js/wp-content/plugins/cf7-otp-sms-verification/vendor/js/main.js/wp-content/plugins/cf7-otp-sms-verification/vendor/js/reset-password.js/wp-content/plugins/cf7-otp-sms-verification/css/admin.css/wp-content/plugins/cf7-otp-sms-verification/vendor/js/admin.js/wp-content/plugins/cf7-otp-sms-verification/vendor/js/alert.js/wp-content/plugins/cf7-otp-sms-verification/vendor/js/main.js/wp-content/plugins/cf7-otp-sms-verification/vendor/js/reset-password.js/wp-content/plugins/cf7-otp-sms-verification/vendor/js/admin.jsHTML / DOM Fingerprints
form_selectorsubmit_btn_selectorinput_requiredmobile_input_namecountry_codeihs_otp_form_selector+8 moreotp_objreset_pass_obj/wp-json/ihs_otp_ajax_hook/wp-json/ihs_otp_reset_ajax_hook