SMS Contact Form 7 Notifications by ClickSend Security & Risk Analysis

wordpress.org/plugins/clicksend-contactform7

Reliable and global SMS notifications for Contact Form 7. ClickSend brings instant SMS communication to the mix. By integrating these tools, you eleva …

100 active installs v1.4.0 PHP + WP 4.0.1+ Updated Dec 7, 2023
contact-form-7lead-formnotificationssmstext-message
63
C · Use Caution
CVEs total1
Unpatched1
Last CVESep 30, 2025
Safety Verdict

Is SMS Contact Form 7 Notifications by ClickSend Safe to Use in 2026?

Use With Caution

Score 63/100

SMS Contact Form 7 Notifications by ClickSend has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Sep 30, 2025Updated 2yr ago
Risk Assessment

The clicksend-contactform7 plugin version 1.4.0 presents a moderate security risk, primarily due to its handling of entry points and its vulnerability history. While the plugin shows some positive signs like a low number of dangerous functions, the absence of capability checks on its sole AJAX handler is a significant concern. This means that any authenticated user, regardless of their role, could potentially trigger this handler, leading to unauthorized actions if the functionality is sensitive.

The static analysis also indicates that a substantial portion of SQL queries are not prepared, and a noticeable percentage of outputs are not properly escaped, which could lead to SQL injection or cross-site scripting vulnerabilities under certain conditions. The absence of any taint analysis findings is positive, suggesting no obvious complex code flows leading to immediate compromise, but it doesn't negate the risks identified in other areas.

The plugin's vulnerability history, specifically a medium severity CVE for Missing Authorization in 2025, aligns with the identified lack of authorization checks. This pattern suggests a recurring issue with access control within the plugin. While there are no currently unpatched critical or high severity vulnerabilities, the presence of a medium one and the identified authorization weakness highlight areas requiring immediate attention and ongoing vigilance. Overall, the plugin has some good practices but requires significant hardening, especially regarding authorization and input validation.

Key Concerns

  • AJAX handler without auth checks
  • SQL queries not using prepared statements
  • Output not properly escaped
  • 1 unpatched medium severity CVE
  • Missing capability checks
Vulnerabilities
1 published

SMS Contact Form 7 Notifications by ClickSend Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62915medium · 4.3Missing Authorization

SMS Contact Form 7 Notifications by ClickSend <= 1.4.0 - Missing Authorization

Sep 30, 2025Unpatched
Version History

SMS Contact Form 7 Notifications by ClickSend Release Timeline

v1.4.0Current1 CVE
v1.3.81 CVE
v1.3.01 CVE
v1.2.21 CVE
v1.1.01 CVE
v1.0.101 CVE
v1.0.91 CVE
v1.0.81 CVE
Code Analysis
Analyzed Mar 16, 2026

SMS Contact Form 7 Notifications by ClickSend Code Analysis

Dangerous Functions
0
Raw SQL Queries
5
4 prepared
Unescaped Output
23
87 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

44% prepared9 total queries

Output Escaping

79% escaped110 total outputs
Attack Surface
1 unprotected

SMS Contact Form 7 Notifications by ClickSend Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_delete_messageincludes\class-clicksend-contactform7-customcode.php:15
WordPress Hooks 12
actionwpcf7_admin_initadmin\clicksend-contactform7-admin-actions.php:7
actionadmin_menuincludes\class-clicksend-contactform7-customcode.php:12
actionwpcf7_admin_initincludes\class-clicksend-contactform7-customcode.php:13
actionplugins_loadedincludes\class-clicksend-contactform7.php:143
actionadmin_enqueue_scriptsincludes\class-clicksend-contactform7.php:159
actionadmin_enqueue_scriptsincludes\class-clicksend-contactform7.php:160
actionwpcf7_initincludes\class-clicksend-contactform7.php:161
actionwp_enqueue_scriptsincludes\class-clicksend-contactform7.php:178
actionwp_enqueue_scriptsincludes\class-clicksend-contactform7.php:179
actionwpcf7_initincludes\class-clicksend-contactform7.php:180
actionwpcf7_mail_sentpublic\clicksend-contactform7-actions.php:6
actionet_pb_contact_form_submitpublic\clicksend-contactform7-actions.php:18
Maintenance & Trust

SMS Contact Form 7 Notifications by ClickSend Maintenance & Trust

Maintenance Signals

WordPress version tested6.3.0
Last updatedDec 7, 2023
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

SMS Contact Form 7 Notifications by ClickSend Developer Profile

clicksend

2 plugins · 200 total installs

76
trust score
Avg Security Score
74/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SMS Contact Form 7 Notifications by ClickSend

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clicksend-contactform7/admin/css/clicksend-contactform7-admin.css/wp-content/plugins/clicksend-contactform7/admin/js/clicksend-contactform7-admin.js
Script Paths
/wp-content/plugins/clicksend-contactform7/admin/js/clicksend-contactform7-admin.js
Version Parameters
clicksend-contactform7/admin/css/clicksend-contactform7-admin.css?ver=clicksend-contactform7/admin/js/clicksend-contactform7-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
clicksend-contactform7-admin
FAQ

Frequently Asked Questions about SMS Contact Form 7 Notifications by ClickSend