Message Bridge for Contact Form 7 and Telegram Security & Risk Analysis

wordpress.org/plugins/cf7-telegram

Deliver Contact Form 7 submissions to Telegram instantly via a bot.

10K active installs v1.0.4 PHP 8.0+ WP 5.6+ Updated Jan 23, 2026
contact-form-7contact-form-telegramtelegram
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 27, 2024
Download
Safety Verdict

Is Message Bridge for Contact Form 7 and Telegram Safe to Use in 2026?

Generally Safe

Score 99/100

Message Bridge for Contact Form 7 and Telegram has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 27, 2024Updated 2mo ago
Risk Assessment

The 'cf7-telegram' v1.0.4 plugin exhibits a generally good security posture based on the static analysis. There are no identified dangerous functions, SQL queries are all prepared, and output is properly escaped. The absence of file operations and external HTTP requests also contributes positively to its security. The total lack of identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) is a significant strength, suggesting limited avenues for direct exploitation.

However, the vulnerability history presents a notable concern. The plugin has one known CVE, categorized as medium severity, with the common vulnerability type being 'Missing Authorization.' While this specific vulnerability is listed as 'currently unpatched: 0', the pattern of past authorization issues, even if resolved in later versions (as implied by it not being unpatched), warrants caution. The lack of capability checks and nonce checks in the static analysis, while not directly indicative of an exploit in this version, could be contributing factors to past authorization vulnerabilities if not handled robustly in other parts of the plugin's lifecycle or if the reported CVE was indeed in a previous version that has since been fixed.

In conclusion, the current version of 'cf7-telegram' appears to have a solid technical foundation with good coding practices evident in the static analysis. The absence of immediate exploitable flaws in this specific analysis is a positive sign. Nevertheless, the historical presence of a medium-severity vulnerability related to missing authorization should not be overlooked, and developers should remain vigilant about authorization checks, especially when considering how the plugin integrates with Contact Form 7 and potentially handles user-submitted data.

Key Concerns

  • Known CVE: Medium severity (Missing Authorization)
  • No capability checks found
  • No nonce checks found
  • Bundled library (Guzzle) - potential for outdated versions
Vulnerabilities
1

Message Bridge for Contact Form 7 and Telegram Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-9629medium · 5.4Missing Authorization

Contact Form 7 + Telegram <= 0.8.5 - Missing Authorization to Authenticated (Subscriber+) Subscription Approve/Pause/Refuse

Oct 27, 2024 Patched in 0.8.6 (2d)
Code Analysis
Analyzed Mar 16, 2026

Message Bridge for Contact Form 7 and Telegram Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

100% escaped1 total outputs
Attack Surface

Message Bridge for Contact Form 7 and Telegram Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitcf7-telegram.php:29
Maintenance & Trust

Message Bridge for Contact Form 7 and Telegram Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 23, 2026
PHP min version8.0
Downloads72K

Community Trust

Rating86/100
Number of ratings20
Active installs10K
Developer Profile

Message Bridge for Contact Form 7 and Telegram Developer Profile

iTRON

7 plugins · 11K total installs

95
trust score
Avg Security Score
93/100
Avg Patch Time
4 days
View full developer profile
Detection Fingerprints

How We Detect Message Bridge for Contact Form 7 and Telegram

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
cf7-telegram/style.css?ver=cf7-telegram/script.js?ver=

HTML / DOM Fingerprints

JS Globals
window.wpcf7tg_ajax_object
Shortcode Output
[telegram]
FAQ

Frequently Asked Questions about Message Bridge for Contact Form 7 and Telegram