
Connect Contact Form 7 to Constant Contact V3 Security & Risk Analysis
wordpress.org/plugins/connect-contact-form-7-to-constant-contact-v3This will connect Contact form 7 (or WooCommerce Checkout) to Constant Contact using the Constant Contact API V3. Requires an API Key and Secret for f …
Is Connect Contact Form 7 to Constant Contact V3 Safe to Use in 2026?
Generally Safe
Score 91/100Connect Contact Form 7 to Constant Contact V3 has a strong security track record. Known vulnerabilities have been patched promptly.
The 'connect-contact-form-7-to-constant-contact-v3' v1.6.1 plugin exhibits a generally good security posture, with no critical or high severity vulnerabilities identified in recent static analysis. The plugin demonstrates good practices by implementing nonce checks and capability checks, and a high percentage of its SQL queries utilize prepared statements. Output escaping is also well-handled, with a significant majority of outputs properly escaped. However, the presence of two flows with unsanitized paths, even without a critical or high severity rating, warrants attention as it indicates potential weaknesses in input sanitization. The vulnerability history reveals one medium severity CVE for Cross-site Scripting, which was patched. While this is positive, it highlights that the plugin has historically been susceptible to XSS, emphasizing the importance of continued vigilance in input handling. The plugin also makes a notable number of external HTTP requests, which, while not inherently a security flaw, can be an attack vector if not handled securely. Overall, the plugin is relatively secure but has areas for improvement, particularly regarding the handling of unsanitized paths and a history of XSS vulnerabilities.
Key Concerns
- Flows with unsanitized paths
- Bundled library Select2
- External HTTP requests
Connect Contact Form 7 to Constant Contact V3 Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Connect Contact Form 7 to Constant Contact <= 1.4 - Reflected Cross-Site Scripting
Connect Contact Form 7 to Constant Contact V3 Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Connect Contact Form 7 to Constant Contact V3 Attack Surface
WordPress Hooks 27
Scheduled Events 1
Maintenance & Trust
Connect Contact Form 7 to Constant Contact V3 Maintenance & Trust
Maintenance Signals
Community Trust
Connect Contact Form 7 to Constant Contact V3 Alternatives
Integration for Constant Contact and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-constant-contact
Send Contact Form 7, WPForms, Elementor, Ninja Forms, Contact Forms Entries data and many other contact form submissions to Constant Contact.
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Connect Contact Form 7 to Constant Contact V3 Developer Profile
6 plugins · 4K total installs
How We Detect Connect Contact Form 7 to Constant Contact V3
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/connect-contact-form-7-to-constant-contact-v3/admin/admin-notices/css/admin-notices.css/wp-content/plugins/connect-contact-form-7-to-constant-contact-v3/admin/admin-notices/js/admin-notices.js/wp-content/plugins/connect-contact-form-7-to-constant-contact-v3/admin/js/custom-script.js/wp-content/plugins/connect-contact-form-7-to-constant-contact-v3/includes/constant-contact-api.js/wp-content/plugins/connect-contact-form-7-to-constant-contact-v3/admin/admin-notices/js/admin-notices.js/wp-content/plugins/connect-contact-form-7-to-constant-contact-v3/admin/js/custom-script.js/wp-content/plugins/connect-contact-form-7-to-constant-contact-v3/includes/constant-contact-api.jsconnect-contact-form-7-to-constant-contact-v3/admin/admin-notices/css/admin-notices.css?ver=connect-contact-form-7-to-constant-contact-v3/admin/admin-notices/js/admin-notices.js?ver=connect-contact-form-7-to-constant-contact-v3/admin/js/custom-script.js?ver=connect-contact-form-7-to-constant-contact-v3/includes/constant-contact-api.js?ver=HTML / DOM Fingerprints
ye-admin-notice<!-- The code that runs during plugin activation --><!-- The code that runs during plugin deactivation --><!-- Scheduled Action Hook. --><!-- Schedule Cron Job Event. -->+2 moredata-ye-notice-iddata-ye-ajax-actiondata-ye-dismiss-scopedata-ye-dismiss-durationwindow.yeAdminNotices