
UniqueID for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/cf7-submission-idAn add-on for Contact Form 7 to add an unique id to every form submission.
Is UniqueID for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100UniqueID for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'cf7-submission-id' version 2.4.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, performing 100% of its SQL queries using prepared statements, and properly escaping a high percentage (96%) of its output. It also has no recorded vulnerability history, suggesting a generally stable codebase. However, significant concerns arise from its attack surface. The plugin exposes two AJAX handlers, both of which completely lack authentication and capability checks. This oversight creates a critical entry point for potential attackers to interact with the plugin's functionality without any validation, which could lead to unauthorized actions or data manipulation if the handler logic is flawed.
Key Concerns
- AJAX handlers without auth checks
- Lack of capability checks
- Lack of nonce checks
UniqueID for Contact Form 7 Security Vulnerabilities
UniqueID for Contact Form 7 Code Analysis
Output Escaping
UniqueID for Contact Form 7 Attack Surface
AJAX Handlers 2
WordPress Hooks 10
Maintenance & Trust
UniqueID for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
UniqueID for Contact Form 7 Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 – Dynamic Text Extension
contact-form-7-dynamic-text-extension
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
UniqueID for Contact Form 7 Developer Profile
1 plugin · 2K total installs
How We Detect UniqueID for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-submission-id/includes/submission_id.js/wp-content/plugins/cf7-submission-id/includes/submission_id.jscf7-submission-id/includes/submission_id.js?ver=2.4.0HTML / DOM Fingerprints
wpcf7-validates-as-numberwpcf7-not-validreadonlyaria-requiredaria-invalidcf7_submission_id_object/wp-json/wp/v2/posts<input type="text"<input type="hidden"