
WeClapp Integration for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/cf7-weclapp-integrationSend user form input to WeClapp to add new contacts/leads/customers recipients.
Is WeClapp Integration for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100WeClapp Integration for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "cf7-weclapp-integration" v1.2.2 presents a mixed security posture. On one hand, the absence of known CVEs and a history of no recorded vulnerabilities suggest a generally secure development practice and a low likelihood of immediate exploitation via known weaknesses. The code also exhibits good practices by utilizing prepared statements for all SQL queries and avoiding external HTTP requests, which are common vectors for vulnerabilities. However, significant concerns arise from the static analysis. The plugin exposes a single AJAX handler without any authentication or capability checks, creating a direct, unprotected entry point. Furthermore, a critical finding is that 100% of its output is not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis found no immediate critical or high-severity flows, the unescaped output and unprotected AJAX handler are substantial weaknesses that attackers could exploit. The plugin's strengths lie in its lack of known vulnerabilities and secure SQL handling, but these are overshadowed by the critical issues of an unprotected AJAX endpoint and pervasive output escaping failures.
Key Concerns
- AJAX handler without authentication check
- 100% of outputs not properly escaped (XSS risk)
- No nonce checks
- No capability checks
WeClapp Integration for Contact Form 7 Security Vulnerabilities
WeClapp Integration for Contact Form 7 Release Timeline
WeClapp Integration for Contact Form 7 Code Analysis
Bundled Libraries
Output Escaping
WeClapp Integration for Contact Form 7 Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
WeClapp Integration for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
WeClapp Integration for Contact Form 7 Alternatives
CleverReach Integration for Contact Form 7
cf7-cleverreach-integration
Connect your Contact Form 7 forms with your CleverReach account.
GSheetConnector for CF7 – Connect Contact Form 7 to Google Sheets and Send Form Submissions in Real Time
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
CF7 Notie
cf7-notie
Display Contact Form 7 response messages as an alternative the standard alert dialog.
CF7 LACRM Connector
lacrm-connector-for-contact-form7
Send your Contact Form 7 data directly to your Less Annoying CRM account.
WeClapp Integration for Contact Form 7 Developer Profile
2 plugins · 710 total installs
How We Detect WeClapp Integration for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf7-weclapp-integration/css/style.css/wp-content/plugins/cf7-weclapp-integration/js/script.js/wp-content/plugins/cf7-weclapp-integration/css/bootstrap.css/wp-content/plugins/cf7-weclapp-integration/js/script.jscf7-weclapp-integration/css/style.css?ver=cf7-weclapp-integration/js/script.js?ver=cf7-weclapp-integration/css/bootstrap.css?ver=HTML / DOM Fingerprints
cf7-weclapp-settings-page<!-- Settings Page for WeClapp Integration --><!-- End Settings Page -->data-weclapp-form-idcf7_weclapp_ajax_object