
Progress Bar for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/cf7-progress-barA clean look progress bar for Contact Form 7 forms. Supports text, select, radio, acceptance fields. Checkboxes are not trackable, maybe available in …
Is Progress Bar for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100Progress Bar for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cf7-progress-bar" v1.0.0 plugin exhibits a generally positive security posture, with no recorded vulnerabilities or critical code signals. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests is commendable. Furthermore, the limited attack surface, consisting of a single shortcode with no apparent authentication issues, is a strong indicator of secure development practices. However, a significant concern lies in the complete lack of output escaping. With 100% of its 6 outputs unescaped, the plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities, which could be exploited by injecting malicious scripts through user-submitted data that is later displayed by the plugin.
The plugin's vulnerability history is clean, with no known CVEs, which is a positive sign. This suggests that the developers may be adhering to secure coding principles. However, the lack of output escaping represents a fundamental security flaw that can be exploited regardless of past vulnerability history. While the plugin has strengths in its limited attack surface and lack of dangerous code patterns, the unescaped output is a critical weakness that needs immediate attention to mitigate the risk of XSS attacks.
Key Concerns
- Unescaped output
Progress Bar for Contact Form 7 Security Vulnerabilities
Progress Bar for Contact Form 7 Code Analysis
Output Escaping
Progress Bar for Contact Form 7 Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Progress Bar for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Progress Bar for Contact Form 7 Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 – Dynamic Text Extension
contact-form-7-dynamic-text-extension
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
Progress Bar for Contact Form 7 Developer Profile
2 plugins · 190 total installs
How We Detect Progress Bar for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-progress-bar/assets/wpcf7apb.js/wp-content/plugins/cf7-progress-bar/assets/wpcf7apb.jsHTML / DOM Fingerprints
wpcf7a-progress-btnwpcf7a-fill<style>.wpcf7a-progress-btn{display: inline-block;height: 10px;width: 30px;background: transparent;border: 1px solid }.wpcf7a-fill{background-color: