Innozilla Skins for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/cf7-skins-innozilla

Auto style Contact Form 7 forms with straightforward dashboard. ( Contact Form 7 Style )

2K active installs v1.1.5 PHP 5.4+ WP 4.0+ Updated Apr 6, 2025
cf7contact-form-7contact-form-7-style
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Innozilla Skins for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Innozilla Skins for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12mo ago
Risk Assessment

The plugin 'cf7-skins-innozilla' v1.1.5 exhibits a strong security posture regarding its attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed. The absence of direct entry points and the presence of nonce and capability checks are positive indicators. Furthermore, the plugin demonstrates good practice by exclusively using prepared statements for SQL queries and avoiding file operations or external HTTP requests.

However, a significant concern arises from the static analysis revealing that only 18% of the 152 output operations are properly escaped. This low rate of proper escaping suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis also identified one flow with an unsanitized path, which, while not currently classified as critical or high, still represents a potential security weakness. The lack of any recorded historical vulnerabilities is a positive sign, suggesting a generally stable codebase, but it does not negate the risks identified in the current static analysis.

In conclusion, while the plugin benefits from a minimal attack surface and good data handling practices for SQL, the substantial portion of unescaped output is a critical weakness. The single unsanitized path also warrants attention. The absence of historical vulnerabilities is encouraging but should not lead to complacency given the identified code-level risks. The overall security is moderate, with a significant risk of XSS due to insufficient output escaping.

Key Concerns

  • Low rate of properly escaped output
  • Flow with unsanitized path found
Vulnerabilities
None known

Innozilla Skins for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Innozilla Skins for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
124
28 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

18% escaped152 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
create_panel_inputs (includes\icf7s-tab.php:274)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Innozilla Skins for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionadmin_noticesclasses\Missing_Dependency_Reporter.php:18
actionadmin_menuincludes\icf7s-admin.php:11
actionadmin_initincludes\icf7s-admin.php:12
actionwpcf7_editor_panelsincludes\icf7s-tab.php:32
actionwpcf7_after_saveincludes\icf7s-tab.php:33
actionwpcf7_after_createincludes\icf7s-tab.php:34
actionwp_enqueue_scriptsincludes\initialize.php:20
actionadmin_enqueue_scriptsincludes\initialize.php:32
actionwpcf7_admin_footerincludes\initialize.php:555
actionwp_footerincludes\initialize.php:556
Maintenance & Trust

Innozilla Skins for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 6, 2025
PHP min version5.4
Downloads28K

Community Trust

Rating80/100
Number of ratings6
Active installs2K
Developer Profile

Innozilla Skins for Contact Form 7 Developer Profile

innozilla

2 plugins · 2K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Innozilla Skins for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-skins-innozilla/css/front_style.css/wp-content/plugins/cf7-skins-innozilla/js/icf7s_configure.js/wp-content/plugins/cf7-skins-innozilla/css/spectrum.css/wp-content/plugins/cf7-skins-innozilla/css/admin_style.css/wp-content/plugins/cf7-skins-innozilla/js/spectrum.js/wp-content/plugins/cf7-skins-innozilla/js/icf7s_configure_admin.js

HTML / DOM Fingerprints

CSS Classes
icf7s-skin-columns-icf7sicf7s-skin-maxwidth-icf7sicf7s-skin-form-center-icf7sicf7s-skin-form-bgcolor-icf7sicf7s-skin-label-fs-icf7sicf7s-skin-label-fc-icf7sicf7s-skin-button_bold-icf7sicf7s-skin-border-size-icf7s+21 more
JS Globals
icf7s_option
Shortcode Output
<style type="text/css"> .wpcf7 :hover, .wpcf7 :active, .wpcf7 :focus{ outline: 0; outline: none; box-shadow: none; } .wpcf7
FAQ

Frequently Asked Questions about Innozilla Skins for Contact Form 7