Contact Form 7 to Mailjet Security & Risk Analysis

wordpress.org/plugins/cf7-to-mailjet

Link Contact Form 7 with Mailjet contact list

600 active installs v1.8 PHP 7.4+ WP 5.0+ Updated Mar 18, 2024
connectorcontact-form-7emailformmailjet
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Contact Form 7 to Mailjet Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 to Mailjet has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin 'cf7-to-mailjet' v1.8 demonstrates a generally good security posture with a zero attack surface from common entry points like AJAX, REST API, shortcodes, and cron events. The absence of known vulnerabilities, including critical or high severity ones, and the lack of recorded past issues is a strong positive indicator. The plugin also performs well in taint analysis, with no critical or high severity flows identified, suggesting inputs are handled with reasonable care.

However, the static analysis reveals a significant concern regarding SQL queries. All two SQL queries are executed without prepared statements, which is a major risk. This practice, especially if any of the data used in these queries originates from user input, could lead to SQL injection vulnerabilities. While the plugin has a nonce check and a capability check, and a high percentage of output is properly escaped, the unmitigated risk from raw SQL queries outweighs these positives. The plugin's historical lack of vulnerabilities is encouraging, but the identified SQL query pattern is a notable weakness that requires immediate attention.

Key Concerns

  • Raw SQL queries without prepared statements
Vulnerabilities
None known

Contact Form 7 to Mailjet Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form 7 to Mailjet Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
0 prepared
Unescaped Output
31
65 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared2 total queries

Output Escaping

68% escaped96 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
ydu_mailjet_form_7 (cf7_to_mailjet.php:60)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Contact Form 7 to Mailjet Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_enqueue_scriptscf7_to_mailjet.php:13
actionadmin_menucf7_to_mailjet.php:35
actionplugins_loadedcf7_to_mailjet.php:43
actionwpcf7_before_send_mailcf7_to_mailjet.php:373
Maintenance & Trust

Contact Form 7 to Mailjet Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMar 18, 2024
PHP min version7.4
Downloads13K

Community Trust

Rating78/100
Number of ratings7
Active installs600
Developer Profile

Contact Form 7 to Mailjet Developer Profile

Youdemus

1 plugin · 600 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 to Mailjet

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf7-to-mailjet/js/admin.js/wp-content/plugins/cf7-to-mailjet/css/admin.css
Script Paths
/wp-content/plugins/cf7-to-mailjet/js/admin.js
Version Parameters
cf7-to-mailjet/js/admin.js?ver=cf7-to-mailjet/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
ydumailjetmf7_admin_emailmcf7_admin_namemcf7_admin_box_to_checkmcf7_admin_mailjet_list_idmf7_fancy_selectmf7_fancy_select_btnmf7_option_group+1 more
HTML Comments
<!-- TODO: Need to move this to js --><!-- <input type="text" name="mf7_list_options[<?php echo $key?>][cf7_list_id]" value="<?php echo esc_attr($option['cf7_list_id']); ?>" placeholder="<?php echo __("Cf7 Forms IDs (obligatoire)", "ydumailjet"); ?>" />-->
Data Attributes
data-id
FAQ

Frequently Asked Questions about Contact Form 7 to Mailjet