
MailRoute – Conditional Email Routing For Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/conditional-email-routing-for-contact-form-7Routes email to different recipients based on form field values in Contact Form 7. A flexible and powerful conditional email routing solution for your …
Is MailRoute – Conditional Email Routing For Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100MailRoute – Conditional Email Routing For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "conditional-email-routing-for-contact-form-7" v1.4.0 demonstrates a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, no raw SQL queries, and no external HTTP requests, which are significant strengths. The presence of nonce and capability checks further indicates an awareness of common WordPress security practices. The complete lack of historical vulnerabilities and unpatched CVEs is also a positive indicator of ongoing security maintenance by the developers.
However, the static analysis does reveal a potential area of concern regarding output escaping. With 41 total outputs and only 44% properly escaped, there's a significant portion where data rendered to the user might not be sufficiently sanitized. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without proper encoding. While the attack surface appears minimal and taint analysis found no issues, the unescaped output is the most prominent actionable risk identified in the code signals.
In conclusion, the plugin is built on a foundation of good security practices, with a clean vulnerability history and minimal attack surface. The primary weakness lies in the incomplete output escaping, which, while not directly flagged by taint analysis in this specific version, represents a potential risk that should be addressed to ensure a robust defense against XSS attacks.
Key Concerns
- Poor output escaping (56% unescaped)
MailRoute – Conditional Email Routing For Contact Form 7 Security Vulnerabilities
MailRoute – Conditional Email Routing For Contact Form 7 Code Analysis
Output Escaping
MailRoute – Conditional Email Routing For Contact Form 7 Attack Surface
WordPress Hooks 6
Maintenance & Trust
MailRoute – Conditional Email Routing For Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
MailRoute – Conditional Email Routing For Contact Form 7 Alternatives
Dynamic Recipients for Contact Form 7
dynamic-recipients-cf7
Add recipient dropdowns to Contact Form 7. Let visitors route their messages to the right person or department without exposing email addresses.
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
MailRoute – Conditional Email Routing For Contact Form 7 Developer Profile
9 plugins · 550 total installs
How We Detect MailRoute – Conditional Email Routing For Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/conditional-email-routing-for-contact-form-7/assets/styles.css/wp-content/plugins/conditional-email-routing-for-contact-form-7/assets/scripts.js/wp-content/plugins/conditional-email-routing-for-contact-form-7/assets/scripts.jsconditional-email-routing-for-contact-form-7/assets/styles.css?ver=1.4.0conditional-email-routing-for-contact-form-7/assets/scripts.js?ver=1.4.0HTML / DOM Fingerprints
cercf7-field-checkboxcercf7-rountingscercf7-roles-headercercf7-header-fieldcercf7-header-conditionscercf7-header-actionname="cercf7_routing_enabled"id="cercf7_routing_enabled"name="cercf7_use_default_email"id="cercf7_use_default_email"id="cercf7_roles"class="cercf7_selected_field_options"window.cercf7_routing_enabledwindow.cercf7_use_default_emailwindow.cercf7_routing_conditions