cf7 woocommerce drop down products list Security & Risk Analysis

wordpress.org/plugins/cf7-woocommerce-product-list-dropdown

For backwards compatibility, if this section is missing, the full length of the short description will be used, and Markdown parsed.

0 active installs v1.1.0 PHP + WP 3.0.1+ Updated May 8, 2019
cf7-woocommerce-product-dropdown-listcommentsproduct-drop-down-listproductswoocommerce-product-list
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is cf7 woocommerce drop down products list Safe to Use in 2026?

Generally Safe

Score 85/100

cf7 woocommerce drop down products list has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The static analysis of "cf7-woocommerce-product-list-dropdown" v1.1.0 indicates a generally positive security posture. The plugin demonstrates good practices by having zero identified dangerous functions, zero SQL queries that are not prepared, and a very high percentage of properly escaped output. The absence of file operations and external HTTP requests further contributes to a reduced attack surface. Notably, the plugin also reports zero known CVEs, suggesting a history of security diligence or a lack of past vulnerabilities being publicly disclosed.

However, there are areas for concern that temper an otherwise strong assessment. The complete absence of Nonce checks and Capability checks across all entry points is a significant weakness. While the static analysis reports zero unprotected entry points, the lack of these fundamental security mechanisms means that if any entry points were to be discovered or if the plugin's functionality expanded, they would be inherently vulnerable to unauthorized access or manipulation. This is a critical oversight that could be exploited if any of the analyzed entry points become exposed or if new ones are introduced.

In conclusion, the plugin exhibits strengths in its clean code and avoidance of common vulnerabilities like raw SQL and improper output escaping. The lack of historical vulnerabilities is also a positive sign. The primary and most significant weakness lies in the complete omission of Nonce and Capability checks. While the current reported attack surface is zero, this omission creates a latent risk that could become critical if the plugin's exposure increases. Therefore, immediate attention should be paid to incorporating these essential security controls.

Key Concerns

  • Missing Nonce checks on all entry points
  • Missing Capability checks on all entry points
Vulnerabilities
None known

cf7 woocommerce drop down products list Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

cf7 woocommerce drop down products list Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
39 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped42 total outputs
Attack Surface

cf7 woocommerce drop down products list Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwpcf7_initcf7wpl.php:64
filterwpcf7_validate_productscf7wpl.php:67
filterwpcf7_validate_products*cf7wpl.php:68
actionadmin_initcf7wpl.php:72
Maintenance & Trust

cf7 woocommerce drop down products list Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMay 8, 2019
PHP min version
Downloads1K

Community Trust

Rating70/100
Number of ratings2
Active installs0
Developer Profile

cf7 woocommerce drop down products list Developer Profile

sortedpixel

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect cf7 woocommerce drop down products list

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
sp-wpcf7-form-control-wrap
Data Attributes
data-name="products"data-name="products*"
Shortcode Output
<select name="</select><option value="
FAQ

Frequently Asked Questions about cf7 woocommerce drop down products list