
Popup for CF7 with Sweet Alert Security & Risk Analysis
wordpress.org/plugins/cf7-sweet-alert-popupPopup for CF7 with Sweet Alert
Is Popup for CF7 with Sweet Alert Safe to Use in 2026?
Use With Caution
Score 63/100Popup for CF7 with Sweet Alert has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'cf7-sweet-alert-popup' plugin version 1.6.5 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed. Furthermore, all SQL queries are using prepared statements, indicating good database security practices. However, a significant concern is the complete lack of output escaping, meaning that data displayed to users is not being properly sanitized, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is ever rendered directly. The plugin also has a single known medium severity vulnerability that remains unpatched, and its history suggests a previous Cross-Site Request Forgery (CSRF) issue, which, combined with the lack of capability checks, raises concerns about how user actions are authenticated and authorized.
Despite the minimal attack surface and secure SQL handling, the lack of output escaping and the presence of an unpatched vulnerability are significant security weaknesses. The absence of capability checks in conjunction with past CSRF issues suggests potential weaknesses in authorization. While the plugin doesn't have critical or high severity issues identified in the taint analysis, the combination of unescaped output and an unpatched CVE warrants caution and prompt attention from users.
Key Concerns
- Unpatched CVE
- 100% output unescaped
- 0 capability checks
Popup for CF7 with Sweet Alert Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Popup for CF7 with Sweet Alert <= 1.6.5 - Cross-Site Request Forgery
Popup for CF7 with Sweet Alert Code Analysis
Output Escaping
Data Flow Analysis
Popup for CF7 with Sweet Alert Attack Surface
WordPress Hooks 6
Maintenance & Trust
Popup for CF7 with Sweet Alert Maintenance & Trust
Maintenance Signals
Community Trust
Popup for CF7 with Sweet Alert Alternatives
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup
wpb-popup-for-contact-form-7
Popup for Contact Form 7 can boost your sales, leads, and conversions. It only takes a few clicks to setup a Contact Form 7 Popup on Button Click.
Form Popup Maker for WPForms, Contact Form 7 and Many other Forms
wpb-form-popup
WPB Popup Form WordPress plugin will help you to create effective form popups. WPForms Popup form, Mailchimp popup, Opt-in, login popup.
Contact Form 7 Popup Response
contact-form-7-popup-response
Contact Form 7 Popup Response helps you to display Contact Form 7 responses or validation messages in a popup
Popup for CF7 with Sweet Alert Developer Profile
1 plugin · 3K total installs
How We Detect Popup for CF7 with Sweet Alert
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-sweet-alert-popup/admin/admin.css/wp-content/plugins/cf7-sweet-alert-popup/assets/css/cf7simplepopup-core.css/wp-content/plugins/cf7-sweet-alert-popup/assets/js/cf7simplepopup-core.js/wp-content/plugins/cf7-sweet-alert-popup/assets/js/sweetalert2.all.min.js/wp-content/plugins/cf7-sweet-alert-popup/assets/js/cf7simplepopup-core.js/wp-content/plugins/cf7-sweet-alert-popup/assets/js/sweetalert2.all.min.jscf7simplepopup-css?ver=1.6.4cf7simplepopup-js?ver=1.6.4sweetalert?ver=1.6.4cf7simplepopup-admin?ver=1.6.4HTML / DOM Fingerprints
premiumButtongoPremiumTextid="cf7simplePopupWidth"id="cf7simplePopupAutoClose"var cf7windowWidthvar cf7simplePopupAutoClose