Contact Form 7 – Show Page Security & Risk Analysis

wordpress.org/plugins/cf7-show-page

A simple WordPress plugin that helps you to know which contact forms are used in the site.

70 active installs v1.0.3 PHP + WP 4.5+ Updated Dec 4, 2018
contact-formcontact-form-7contactform7formforms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Contact Form 7 – Show Page Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 – Show Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "cf7-show-page" v1.0.3 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unsanitized taint flows, raw SQL queries, or unprotected entry points like AJAX handlers, REST API routes, or shortcodes is commendable. The code also demonstrates good practices with a high percentage of properly escaped output and a significant number of nonce and capability checks, indicating a conscious effort to secure against common web vulnerabilities. Furthermore, the plugin's history of zero known CVEs, across all severity levels, suggests a mature and secure development process.

While the overall security is very good, the "Total entry points: 0, Unprotected: 0" signal is somewhat concerning. An attack surface of zero is highly unusual for a plugin that likely interacts with WordPress functionality. This could imply either a very simple plugin with no user-facing or administrative interaction points, or it might indicate limitations in the static analysis tool's ability to detect certain types of entry points. However, given the otherwise robust security signals and clean vulnerability history, this is likely not a significant practical risk, but rather an anomaly in reporting or an indicator of a plugin with extremely limited scope.

In conclusion, "cf7-show-page" v1.0.3 appears to be a secure plugin with a clean bill of health in its static analysis and vulnerability history. The development team has implemented several key security measures effectively. The only minor point of note is the reported zero attack surface, which warrants a slight caution due to its unusual nature, but does not detract from the plugin's otherwise excellent security standing.

Key Concerns

  • Reported zero attack surface is unusual and warrants slight caution
Vulnerabilities
None known

Contact Form 7 – Show Page Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form 7 – Show Page Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
9
89 escaped
Nonce Checks
5
Capability Checks
14
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

91% escaped98 total outputs
Attack Surface

Contact Form 7 – Show Page Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 27
actionadmin_footercontact-form-7-show-page.php:33
filterwpcf7_editor_panelscontact-form-7-show-page.php:55
actiontgmpa_registertgmpa\call.php:36
actioninittgmpa\class-tgm-plugin-activation.php:268
filterload_textdomain_mofiletgmpa\class-tgm-plugin-activation.php:269
actioninittgmpa\class-tgm-plugin-activation.php:272
actionadmin_menutgmpa\class-tgm-plugin-activation.php:421
actionadmin_headtgmpa\class-tgm-plugin-activation.php:422
filterinstall_plugin_complete_actionstgmpa\class-tgm-plugin-activation.php:425
filterupdate_plugin_complete_actionstgmpa\class-tgm-plugin-activation.php:426
actionadmin_noticestgmpa\class-tgm-plugin-activation.php:429
actionadmin_inittgmpa\class-tgm-plugin-activation.php:430
actionadmin_enqueue_scriptstgmpa\class-tgm-plugin-activation.php:431
actionload-plugins.phptgmpa\class-tgm-plugin-activation.php:436
actionswitch_themetgmpa\class-tgm-plugin-activation.php:439
actionswitch_themetgmpa\class-tgm-plugin-activation.php:442
actionadmin_inittgmpa\class-tgm-plugin-activation.php:447
actionswitch_themetgmpa\class-tgm-plugin-activation.php:452
actionload_textdomain_mofiletgmpa\class-tgm-plugin-activation.php:475
filterupgrader_source_selectiontgmpa\class-tgm-plugin-activation.php:889
actionplugins_loadedtgmpa\class-tgm-plugin-activation.php:2112
filtertgmpa_table_data_itemstgmpa\class-tgm-plugin-activation.php:2236
filterupgrader_source_selectiontgmpa\class-tgm-plugin-activation.php:2977
actionadmin_inittgmpa\class-tgm-plugin-activation.php:3147
actionupgrader_process_completetgmpa\class-tgm-plugin-activation.php:3242
filterupgrader_post_installtgmpa\class-tgm-plugin-activation.php:3301
filterupgrader_post_installtgmpa\class-tgm-plugin-activation.php:3446
Maintenance & Trust

Contact Form 7 – Show Page Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedDec 4, 2018
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings3
Active installs70
Developer Profile

Contact Form 7 – Show Page Developer Profile

Sachyya

2 plugins · 570 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 – Show Page

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-show-page/css/show-page.css

HTML / DOM Fingerprints

CSS Classes
wpcf7spwpcf7sp-optwpcf7sp-alink
FAQ

Frequently Asked Questions about Contact Form 7 – Show Page