
SMS Extension for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/cf7-sms-extensionReceive text message notifications when a form is submitted.
Is SMS Extension for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100SMS Extension for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cf7-sms-extension" v1.3.6.1 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the use of prepared statements for all SQL queries are positive indicators. However, the analysis reveals significant areas for concern. Notably, the plugin performs external HTTP requests, which can be a vector for various attacks if not handled with extreme care and proper validation. The low percentage of properly escaped output (51%) is a substantial risk, suggesting that user-supplied data, if processed in these unescaped contexts, could lead to cross-site scripting (XSS) vulnerabilities. Furthermore, the complete lack of nonce checks and capability checks on any entry points is a critical oversight, leaving the plugin vulnerable to cross-site request forgery (CSRF) and privilege escalation attacks, especially if any new entry points are introduced or if the current, albeit zero, attack surface were to be exploited through other means.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
- Bundled Freemius v1.0 library
SMS Extension for Contact Form 7 Security Vulnerabilities
SMS Extension for Contact Form 7 Release Timeline
SMS Extension for Contact Form 7 Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
SMS Extension for Contact Form 7 Attack Surface
WordPress Hooks 10
Maintenance & Trust
SMS Extension for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
SMS Extension for Contact Form 7 Alternatives
Texty – SMS Notification for WordPress, WooCommerce, Dokan and more
texty
Texty is a lightweight SMS notification plugin for WordPress.
SocialNotify: Notifications for Contact Form 7
eca-socialnotify-cf7
WhatsApp Notification for Contact Form 7 – Send WhatsApp messages using Twilio API when a form is submitted.
NotifSMS – SMS Notifications OTP & 2FA for WordPress & WooCommerce
wp-twilio-core
Send SMS, OTP & 2FA notifications from WordPress via Twilio. Includes automated alerts, bulk messaging, and integrations with popular plugins.
Notifications for Forms & WordPress Actions
notifier
Send WhatsApp notifications for form submissions from CF7, Gravity Forms, WPForms and more and WordPress actions using WhatsApp Business API
ShopMagic – Twilio SMS
shopmagic-for-twilio
Send WooCommerce SMS notifications, reminders, and text messages to your customers. The plugin is the ShopMagic add-on and it lets you send sms remind …
SMS Extension for Contact Form 7 Developer Profile
3 plugins · 1K total installs
How We Detect SMS Extension for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-sms-extension/includes/freemius/assets/css/freemius-sdk.css/wp-content/plugins/cf7-sms-extension/includes/freemius/assets/js/freemius-sdk.js/wp-content/plugins/cf7-sms-extension/includes/freemius/start.phpcf7-sms-extension/includes/freemius/assets/css/freemius-sdk.css?ver=cf7-sms-extension/includes/freemius/assets/js/freemius-sdk.js?ver=HTML / DOM Fingerprints
kmcf7se-sms-extension-optionsdata-fs-product-id="13504"data-fs-slug="cf7-sms-extension"kmcf7se_fs