Contact Form 7: Support Deprecated Settings Security & Risk Analysis

wordpress.org/plugins/cf7-support-deprecated-settings

Provide continued support for on_sent_ok and on_submit within Contact Form 7's Additional Settings

10 active installs v0.4 PHP 5.3+ WP 4.0+ Updated Feb 2, 2018
contactcontact-formemailformjavascript
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form 7: Support Deprecated Settings Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7: Support Deprecated Settings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of "cf7-support-deprecated-settings" v0.4 reveals a seemingly strong security posture with no identified dangerous functions, SQL queries without prepared statements, unsanitized outputs, file operations, external HTTP requests, or vulnerable taint flows. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, and importantly, all entry points (0 total, 0 unprotected) appear to be secured. The vulnerability history is also clean, with no known CVEs, indicating a likely responsible development history or that the plugin has not been a significant target. However, the complete lack of nonce checks and capability checks across all analyzed code is a notable concern. While the current analysis shows no direct vulnerabilities, this absence of fundamental security measures means that if any new entry points are introduced or existing ones are overlooked in future development or analysis, they would be immediately exposed to various attacks, such as Cross-Site Request Forgery (CSRF) or unauthorized access. Therefore, despite the current lack of identified issues, the plugin's security is heavily reliant on its limited attack surface, and the absence of these common security checks represents a potential weakness for future expansion or evolving threats.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Contact Form 7: Support Deprecated Settings Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Contact Form 7: Support Deprecated Settings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Contact Form 7: Support Deprecated Settings Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filterwpcf7_form_response_outputclasses\cf7-support-deprecated-settings.php:27
actionwpcf7_submitclasses\cf7-support-deprecated-settings.php:31
filterwpcf7_ajax_json_echoclasses\cf7-support-deprecated-settings.php:32
Maintenance & Trust

Contact Form 7: Support Deprecated Settings Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedFeb 2, 2018
PHP min version5.3
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Contact Form 7: Support Deprecated Settings Developer Profile

Dave McHale

5 plugins · 90K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7: Support Deprecated Settings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-support-deprecated-settings/

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Contact Form 7: Support Deprecated Settings