Connect Contact Form 7 to Salesforce Security & Risk Analysis

wordpress.org/plugins/connect-cf7-to-salesforce

Seamlessly integrate Contact Form 7 with Salesforce to automate your lead management process.

10 active installs v1.0.0 PHP 8.0+ WP 5.3+ Updated Sep 26, 2024
connectioncontact-form-7crmsalesforce
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Connect Contact Form 7 to Salesforce Safe to Use in 2026?

Generally Safe

Score 92/100

Connect Contact Form 7 to Salesforce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "connect-cf7-to-salesforce" plugin v1.0.0 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping almost all of its output. The absence of known vulnerabilities in its history is also a significant strength, suggesting a history of responsible development or a lack of past security scrutiny. However, the plugin has a critical security weakness due to its attack surface.

Specifically, there are two AJAX handlers, and concerningly, both lack authentication checks. This means any unauthenticated user could potentially interact with these handlers, creating a significant risk. While taint analysis shows no immediate exploitable flows, the presence of unprotected entry points into the application is a serious concern that could be leveraged in conjunction with other vulnerabilities or by exploiting flaws in the handled data. The plugin also relies on the Guzzle library, which, if outdated, could introduce further risks, though no specific information on its version is provided.

In conclusion, while the plugin exhibits strengths in its handling of database queries and output, the unprotected AJAX endpoints are a major security flaw that overshadows these positives. The lack of historical vulnerabilities is reassuring but does not negate the current, clear risks identified in the static analysis. Users should be aware of the potential for unauthorized access and execution through the AJAX handlers.

Key Concerns

  • Unprotected AJAX handlers
  • Reliance on bundled library (potential)
Vulnerabilities
None known

Connect Contact Form 7 to Salesforce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Connect Contact Form 7 to Salesforce Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Connect Contact Form 7 to Salesforce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
45 escaped
Nonce Checks
6
Capability Checks
1
File Operations
1
External Requests
2
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

96% escaped47 total outputs
Attack Surface
2 unprotected

Connect Contact Form 7 to Salesforce Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_login_to_salesforceconnect-cf7-to-salesforce.php:86
authwp_ajax_revoke_tokenconnect-cf7-to-salesforce.php:87
WordPress Hooks 6
actionadmin_initconnect-cf7-to-salesforce.php:89
actioninitconnect-cf7-to-salesforce.php:91
actionwpcf7_before_send_mailconnect-cf7-to-salesforce.php:92
actionplugins_loadedconnect-cf7-to-salesforce.php:103
actionadmin_menusrc\Admin\RegisterMenu.php:28
actionadmin_enqueue_scriptssrc\Admin\ScriptsManager.php:23
Maintenance & Trust

Connect Contact Form 7 to Salesforce Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 26, 2024
PHP min version8.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Connect Contact Form 7 to Salesforce Developer Profile

Procoders

7 plugins · 410 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Connect Contact Form 7 to Salesforce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/connect-cf7-to-salesforce/Assets/css/admin.css/wp-content/plugins/connect-cf7-to-salesforce/Assets/js/admin.js
Script Paths
/wp-content/plugins/connect-cf7-to-salesforce/Assets/js/admin.js
Version Parameters
connect-cf7-to-salesforce/Assets/css/admin.css?ver=connect-cf7-to-salesforce/Assets/js/admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-cf7sf-field-map
JS Globals
wp_ajax_obj
FAQ

Frequently Asked Questions about Connect Contact Form 7 to Salesforce