
SMS Extension for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/cf7-sms-extensionReceive text message notifications when a form is submitted.
Is SMS Extension for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100SMS Extension for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cf7-sms-extension" v1.3.6.1 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the use of prepared statements for all SQL queries are positive indicators. However, the analysis reveals significant areas for concern. Notably, the plugin performs external HTTP requests, which can be a vector for various attacks if not handled with extreme care and proper validation. The low percentage of properly escaped output (51%) is a substantial risk, suggesting that user-supplied data, if processed in these unescaped contexts, could lead to cross-site scripting (XSS) vulnerabilities. Furthermore, the complete lack of nonce checks and capability checks on any entry points is a critical oversight, leaving the plugin vulnerable to cross-site request forgery (CSRF) and privilege escalation attacks, especially if any new entry points are introduced or if the current, albeit zero, attack surface were to be exploited through other means.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
- Bundled Freemius v1.0 library
SMS Extension for Contact Form 7 Security Vulnerabilities
SMS Extension for Contact Form 7 Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
SMS Extension for Contact Form 7 Attack Surface
WordPress Hooks 10
Maintenance & Trust
SMS Extension for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
SMS Extension for Contact Form 7 Alternatives
Texty – SMS Notification for WordPress, WooCommerce, Dokan and more
texty
Texty is a lightweight SMS notification plugin for WordPress.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
TextMe SMS
textme-sms-integration
Send custom SMS messages from your WordPress site to your customers using the TextMe SMS gateway.
Contact Widgets For Elementor all the contact links you need in one place
contact-widgets-for-elementor
Contact Widgets For Elementor , Now you can add all the beast ways to contact you: Whatsapp, SMS, Facebook messenger, Email, Phone and Waze.
SMS Extension for Contact Form 7 Developer Profile
3 plugins · 1K total installs
How We Detect SMS Extension for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-sms-extension/includes/freemius/assets/css/freemius-sdk.css/wp-content/plugins/cf7-sms-extension/includes/freemius/assets/js/freemius-sdk.js/wp-content/plugins/cf7-sms-extension/includes/freemius/start.phpcf7-sms-extension/includes/freemius/assets/css/freemius-sdk.css?ver=cf7-sms-extension/includes/freemius/assets/js/freemius-sdk.js?ver=HTML / DOM Fingerprints
kmcf7se-sms-extension-optionsdata-fs-product-id="13504"data-fs-slug="cf7-sms-extension"kmcf7se_fs