
Contact Form 7 – Repeatable Fields Security & Risk Analysis
wordpress.org/plugins/cf7-repeatable-fieldsAdds repeatable groups of fields to Contact Form 7.
Is Contact Form 7 – Repeatable Fields Safe to Use in 2026?
Generally Safe
Score 91/100Contact Form 7 – Repeatable Fields has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of cf7-repeatable-fields v2.0.2 shows a generally good security posture with no identified dangerous functions, SQL queries using prepared statements, or file operations. The absence of AJAX handlers, REST API routes, shortcodes, and cron events contributing to the attack surface is also a positive sign. However, the code analysis does reveal some areas for improvement, notably the presence of unescaped output, with 25% of identified outputs not being properly escaped. While the taint analysis shows no critical or high severity flows, this still indicates a potential weakness. The vulnerability history reveals one past CVE, which was a Cross-site Scripting (XSS) vulnerability. The fact that this vulnerability is now patched is positive, but the existence of a past XSS vulnerability, even if resolved, warrants continued vigilance. Overall, while the plugin exhibits strong practices in many areas, the unescaped output and past XSS vulnerability suggest a moderate risk that should be monitored.
Key Concerns
- Unescaped output identified
- Past Cross-site Scripting (XSS) vulnerability history
Contact Form 7 – Repeatable Fields Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Contact Form 7 - Repeatable Fields <= 2.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via field_group Shortcode
Contact Form 7 – Repeatable Fields Code Analysis
Output Escaping
Contact Form 7 – Repeatable Fields Attack Surface
WordPress Hooks 4
Maintenance & Trust
Contact Form 7 – Repeatable Fields Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 – Repeatable Fields Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Advanced Contact form 7 DB
advanced-cf7-db
Save all contact form 7 form submitted data to the database, View, Ordering, Change field labels and Import/Export data using CSV.
Connect Contact Form 7 and Mailchimp
contact-form-7-mailchimp-extension
Connect Contact Form 7 to Mailchimp. Automatically sync form submissions to your Mailchimp audiences with merge field mapping, double opt-in, and opt- …
Contact Form 7 Multi-Step Forms
contact-form-7-multi-step-module
Enables the Contact Form 7 plugin to create multi-page, multi-step forms.
Contact Form 7 – Repeatable Fields Developer Profile
3 plugins · 6K total installs
How We Detect Contact Form 7 – Repeatable Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-repeatable-fields/assets/js/scripts.js/wp-content/plugins/cf7-repeatable-fields/dist/scripts.js/wp-content/plugins/cf7-repeatable-fields/assets/js/scripts.js/wp-content/plugins/cf7-repeatable-fields/dist/scripts.jscf7-repeatable-fields/assets/js/scripts.js?ver=cf7-repeatable-fields/dist/scripts.js?ver=HTML / DOM Fingerprints
wpcf7-field-groupswpcf7-field-group-addwpcf7-field-group-removewpcf7-field-group-countwpcf7-field-groupdata-wpcf7-group-id<button type='button' class='wpcf7-field-group-add<button type='button' class='wpcf7-field-group-remove<input type="hidden" class="wpcf7-field-group-count" name="_wpcf7_groups_count[