
CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Security & Risk Analysis
wordpress.org/plugins/cf7-submissionsSecurely Store and Manage CF7 Submissions Hassle-Free
Is CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Safe to Use in 2026?
Mostly Safe
Score 78/100CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more is generally safe to use. 1 past CVE were resolved. Keep it updated.
The "cf7-submissions" plugin v0.26 exhibits a generally good security posture based on the static analysis. It demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and ensuring all output is properly escaped. The absence of critical or high severity taint flows further suggests that sensitive data is handled with care. The plugin also incorporates a reasonable number of nonce and capability checks, contributing to its defensibility against common web attacks.
However, a significant concern arises from the plugin's vulnerability history, which shows one known medium severity CVE that is currently unpatched. The common vulnerability type listed as "Missing Authorization" in past incidents, even if this specific unpatched CVE is not directly related, indicates a historical pattern that warrants caution. While the current static analysis doesn't reveal obvious entry points without authentication, the past trend of authorization issues means that the unpatched CVE could potentially be exploited by unauthorized users.
In conclusion, while the code itself appears robust with good practices in place for SQL and output handling, the presence of an unpatched medium severity vulnerability and a history of authorization issues presents a notable risk. Users should be aware of this outstanding vulnerability and its potential implications, especially given the plugin's past security challenges.
Key Concerns
- Unpatched medium severity CVE
- History of missing authorization vulnerabilities
CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CF7 Submissions <= 0.26 - Missing Authorization
CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Attack Surface
Scheduled Events 1
Maintenance & Trust
CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Maintenance & Trust
Maintenance Signals
Community Trust
CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Alternatives
Entries For CF7
entries-for-cf7
Thanks For using our plugin.
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more Developer Profile
10 plugins · 41K total installs
How We Detect CF7 Submissions – Securely Store Contact Form 7 Data and Attachments, Reply to the Sender and more
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-submissions/assets/css/chosen.min.css/wp-content/plugins/cf7-submissions/assets/js/chosen.jquery.min.js/wp-content/plugins/cf7-submissions/assets/css/admin.css/wp-content/plugins/cf7-submissions/assets/js/admin.js/wp-content/plugins/cf7-submissions/assets/js/custom.js/wp-content/plugins/cf7-submissions/assets/css/custom.css/wp-content/plugins/cf7-submissions/assets/js/chosen.jquery.min.js/wp-content/plugins/cf7-submissions/assets/js/admin.js/wp-content/plugins/cf7-submissions/assets/js/custom.jscf7-submissions/assets/css/chosen.min.css?ver=cf7-submissions/assets/js/chosen.jquery.min.js?ver=cf7-submissions/assets/css/admin.css?ver=cf7-submissions/assets/js/admin.js?ver=cf7-submissions/assets/js/custom.js?ver=cf7-submissions/assets/css/custom.css?ver=HTML / DOM Fingerprints
cf7s-deletecf7s-restorecf7s-readcf7s-unreadcf7s-bulk-actionscf7s-contact-formcf7s-submision-idcf7s-submission-date+11 more<!-- cf7-submissions --><!-- .cf7-submissions --><!-- END .cf7-submissions --><!-- CF7 Submissions -->+3 moredata-cf7s-iddata-cf7s-actiondata-cf7s-noncedata-cf7s-modal-targetcf7s_localizecf7_submissions_params/wp-json/cf7s/v1/submissions