Contact Form 7 to Robly Security & Risk Analysis

wordpress.org/plugins/cf7-robly

Adds Contact Form 7 submission information to one or more Robly lists, including custom fields.

30 active installs v1.2.5 PHP + WP 4.3+ Updated Sep 27, 2017
cf7contact-formcontact-form-7formforms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form 7 to Robly Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 to Robly has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "cf7-robly" plugin v1.2.5 exhibits a generally strong security posture based on the provided static analysis. The complete absence of direct attack surface points like AJAX handlers, REST API routes, shortcodes, and cron events is a significant positive. Furthermore, the plugin demonstrates good practices by using prepared statements for all SQL queries, indicating protection against SQL injection. The lack of any recorded CVEs also suggests a history of security diligence or a lack of discovery.

However, there are areas of concern. The low percentage of properly escaped output (33%) is a notable weakness. This implies that a majority of the data being outputted by the plugin might not be adequately sanitized, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully before display. The absence of nonce checks and capability checks, while not directly exploitable due to the lack of entry points, represents a missed opportunity for layered security. If future versions introduce new entry points without these checks, it could expose the plugin to vulnerabilities.

In conclusion, the plugin has a solid foundation with no readily apparent vulnerabilities in its current configuration and history. Its lack of direct entry points and secure SQL handling are commendable. The primary risk lies in the insufficient output escaping, which requires careful attention in any future development or if user-provided data is ever incorporated into outputs. The missed opportunity for nonce and capability checks, while not a current exploit, points to a potential for future issues if not addressed.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Contact Form 7 to Robly Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Contact Form 7 to Robly Release Timeline

v1.2.5Current
v1.2.4
v1.2.3
v1.2.2
v1.2.1
Code Analysis
Analyzed Apr 16, 2026

Contact Form 7 to Robly Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
1

Bundled Libraries

jQuery

Output Escaping

33% escaped9 total outputs
Attack Surface

Contact Form 7 to Robly Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_enqueue_scriptscf7-robly.php:19
actionadmin_menucf7-robly.php:28
actionadmin_initcf7-robly.php:29
actionwpcf7_add_meta_boxescf7-robly.php:191
filterwpcf7_editor_panelscf7-robly.php:367
actionwpcf7_save_contact_formcf7-robly.php:381
actionwpcf7_before_send_mailcf7-robly.php:431
Maintenance & Trust

Contact Form 7 to Robly Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 27, 2017
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

Contact Form 7 to Robly Developer Profile

macbookandrew

12 plugins · 8K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
498 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 to Robly

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-robly/css/cf7-robly.min.css/wp-content/plugins/cf7-robly/js/backend.min.js/wp-content/plugins/cf7-robly/js/chosen.jquery.min.js/wp-content/plugins/cf7-robly/css/chosen.min.css
Script Paths
/wp-content/plugins/cf7-robly/js/chosen.jquery.min.js/wp-content/plugins/cf7-robly/js/backend.min.js
Version Parameters
cf7-robly/css/cf7-robly.min.css?ver=cf7-robly/js/backend.min.js?ver=cf7-robly/js/chosen.jquery.min.js?ver=cf7-robly/css/chosen.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
cf7-robly-settings
HTML Comments
prevent this file from being accessed directlyAdd your API KeysAPI settingsAlternate Email+13 more
Data Attributes
name="cf7_robly_settings[cf7_robly_api_id]"name="cf7_robly_settings[cf7_robly_api_key]"name="cf7_robly_settings[cf7_robly_alternate_email]"
JS Globals
window.cf7_robly_settings
FAQ

Frequently Asked Questions about Contact Form 7 to Robly