
SMS Contact Form 7 Notifications by ClickSend Security & Risk Analysis
wordpress.org/plugins/clicksend-contactform7Reliable and global SMS notifications for Contact Form 7. ClickSend brings instant SMS communication to the mix. By integrating these tools, you eleva …
Is SMS Contact Form 7 Notifications by ClickSend Safe to Use in 2026?
Use With Caution
Score 63/100SMS Contact Form 7 Notifications by ClickSend has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The clicksend-contactform7 plugin version 1.4.0 presents a moderate security risk, primarily due to its handling of entry points and its vulnerability history. While the plugin shows some positive signs like a low number of dangerous functions, the absence of capability checks on its sole AJAX handler is a significant concern. This means that any authenticated user, regardless of their role, could potentially trigger this handler, leading to unauthorized actions if the functionality is sensitive.
The static analysis also indicates that a substantial portion of SQL queries are not prepared, and a noticeable percentage of outputs are not properly escaped, which could lead to SQL injection or cross-site scripting vulnerabilities under certain conditions. The absence of any taint analysis findings is positive, suggesting no obvious complex code flows leading to immediate compromise, but it doesn't negate the risks identified in other areas.
The plugin's vulnerability history, specifically a medium severity CVE for Missing Authorization in 2025, aligns with the identified lack of authorization checks. This pattern suggests a recurring issue with access control within the plugin. While there are no currently unpatched critical or high severity vulnerabilities, the presence of a medium one and the identified authorization weakness highlight areas requiring immediate attention and ongoing vigilance. Overall, the plugin has some good practices but requires significant hardening, especially regarding authorization and input validation.
Key Concerns
- AJAX handler without auth checks
- SQL queries not using prepared statements
- Output not properly escaped
- 1 unpatched medium severity CVE
- Missing capability checks
SMS Contact Form 7 Notifications by ClickSend Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
SMS Contact Form 7 Notifications by ClickSend <= 1.4.0 - Missing Authorization
SMS Contact Form 7 Notifications by ClickSend Release Timeline
SMS Contact Form 7 Notifications by ClickSend Code Analysis
SQL Query Safety
Output Escaping
SMS Contact Form 7 Notifications by ClickSend Attack Surface
AJAX Handlers 1
WordPress Hooks 12
Maintenance & Trust
SMS Contact Form 7 Notifications by ClickSend Maintenance & Trust
Maintenance Signals
Community Trust
SMS Contact Form 7 Notifications by ClickSend Alternatives
TextMe SMS
textme-sms-integration
Send custom SMS messages from your WordPress site to your customers using the TextMe SMS gateway.
Transmit SMS Share
transmit-sms-share
Share pages, posts and links via SMS using Transmit SMS API
Sendit Israel
sendit-israel
Sendit Israel provides a simple SMS integration for WordPress and WooCommerce. Supports order status SMS notifications and Contact Form 7 submissions.
WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce
wp-sms
Send SMS/MMS notifications, OTP & 2FA messages, and WooCommerce updates with support for multiple gateways and plugin integrations.
miniOrange OTP Login, Verification and SMS Notifications
miniorange-otp-verification
OTP Verification via Email/SMS/WhatsApp,SMS Notifications for WooCommerce,OTP Login with Phone,PasswordLess Login.Custom Gateway for OTP Verification
SMS Contact Form 7 Notifications by ClickSend Developer Profile
2 plugins · 200 total installs
How We Detect SMS Contact Form 7 Notifications by ClickSend
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clicksend-contactform7/admin/css/clicksend-contactform7-admin.css/wp-content/plugins/clicksend-contactform7/admin/js/clicksend-contactform7-admin.js/wp-content/plugins/clicksend-contactform7/admin/js/clicksend-contactform7-admin.jsclicksend-contactform7/admin/css/clicksend-contactform7-admin.css?ver=clicksend-contactform7/admin/js/clicksend-contactform7-admin.js?ver=HTML / DOM Fingerprints
clicksend-contactform7-admin