
Contact Form 7 – Show Page Security & Risk Analysis
wordpress.org/plugins/cf7-show-pageA simple WordPress plugin that helps you to know which contact forms are used in the site.
Is Contact Form 7 – Show Page Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form 7 – Show Page has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cf7-show-page" v1.0.3 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, unsanitized taint flows, raw SQL queries, or unprotected entry points like AJAX handlers, REST API routes, or shortcodes is commendable. The code also demonstrates good practices with a high percentage of properly escaped output and a significant number of nonce and capability checks, indicating a conscious effort to secure against common web vulnerabilities. Furthermore, the plugin's history of zero known CVEs, across all severity levels, suggests a mature and secure development process.
While the overall security is very good, the "Total entry points: 0, Unprotected: 0" signal is somewhat concerning. An attack surface of zero is highly unusual for a plugin that likely interacts with WordPress functionality. This could imply either a very simple plugin with no user-facing or administrative interaction points, or it might indicate limitations in the static analysis tool's ability to detect certain types of entry points. However, given the otherwise robust security signals and clean vulnerability history, this is likely not a significant practical risk, but rather an anomaly in reporting or an indicator of a plugin with extremely limited scope.
In conclusion, "cf7-show-page" v1.0.3 appears to be a secure plugin with a clean bill of health in its static analysis and vulnerability history. The development team has implemented several key security measures effectively. The only minor point of note is the reported zero attack surface, which warrants a slight caution due to its unusual nature, but does not detract from the plugin's otherwise excellent security standing.
Key Concerns
- Reported zero attack surface is unusual and warrants slight caution
Contact Form 7 – Show Page Security Vulnerabilities
Contact Form 7 – Show Page Code Analysis
SQL Query Safety
Output Escaping
Contact Form 7 – Show Page Attack Surface
WordPress Hooks 27
Maintenance & Trust
Contact Form 7 – Show Page Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 – Show Page Alternatives
Contact Form 7 Signature Addon
contact-form-7-signature-addon
Easily add an handwritten signature field to Contact Form 7
Contact Form 7 Phone Module
contact-form-7-phone-mask-module
Adds phone module to the Contact Form 7 plugin
Contact Form 7 Map Field
contact-form-7-map-field
This plugin provides a new field to Contact Form 7: a map with a coordinates marker, letting the user mark a location.
Contact Form 7 Multiple Upload Addon
cf7-multiupload
The WordPress Plugin Contact Form 7 Multiple Uploads Addon supports uploading multiple files at the same time within the contact form.
Contact Form 7 Tag field
contact-form-7-tag-field
Contact Form 7 - Add a new field to the module that enables the user to add tags to his message via a tag field.
Contact Form 7 – Show Page Developer Profile
2 plugins · 570 total installs
How We Detect Contact Form 7 – Show Page
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-show-page/css/show-page.cssHTML / DOM Fingerprints
wpcf7spwpcf7sp-optwpcf7sp-alink