
Contact Form 7: Support Deprecated Settings Security & Risk Analysis
wordpress.org/plugins/cf7-support-deprecated-settingsProvide continued support for on_sent_ok and on_submit within Contact Form 7's Additional Settings
Is Contact Form 7: Support Deprecated Settings Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form 7: Support Deprecated Settings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "cf7-support-deprecated-settings" v0.4 reveals a seemingly strong security posture with no identified dangerous functions, SQL queries without prepared statements, unsanitized outputs, file operations, external HTTP requests, or vulnerable taint flows. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, and importantly, all entry points (0 total, 0 unprotected) appear to be secured. The vulnerability history is also clean, with no known CVEs, indicating a likely responsible development history or that the plugin has not been a significant target. However, the complete lack of nonce checks and capability checks across all analyzed code is a notable concern. While the current analysis shows no direct vulnerabilities, this absence of fundamental security measures means that if any new entry points are introduced or existing ones are overlooked in future development or analysis, they would be immediately exposed to various attacks, such as Cross-Site Request Forgery (CSRF) or unauthorized access. Therefore, despite the current lack of identified issues, the plugin's security is heavily reliant on its limited attack surface, and the absence of these common security checks represents a potential weakness for future expansion or evolving threats.
Key Concerns
- Missing nonce checks
- Missing capability checks
Contact Form 7: Support Deprecated Settings Security Vulnerabilities
Contact Form 7: Support Deprecated Settings Code Analysis
Contact Form 7: Support Deprecated Settings Attack Surface
WordPress Hooks 3
Maintenance & Trust
Contact Form 7: Support Deprecated Settings Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7: Support Deprecated Settings Alternatives
GM Contact Form
gm-contact-form
A simple foolproof contact form for WordPress.
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
HTML Forms – Simple WordPress Forms Plugin
html-forms
A simpler, faster, and smarter WordPress forms plugin.
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress
wpzoom-forms
Drag & drop contact form builder for WordPress. Create contact forms, custom forms, email forms with spam protection. Works with Elementor, shortcodes
Contact Form 7: Support Deprecated Settings Developer Profile
5 plugins · 90K total installs
How We Detect Contact Form 7: Support Deprecated Settings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-support-deprecated-settings/