
Contact Form 7 – Campaign Monitor Addon Security & Risk Analysis
wordpress.org/plugins/contact-form-7-campaignmonitor-addonAdd the capability to create newsletter opt-in forms with Contact Form 7. Automatically submit subscribers to predetermined lists in Campaign Monitor.
Is Contact Form 7 – Campaign Monitor Addon Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form 7 – Campaign Monitor Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "contact-form-7-campaignmonitor-addon" v1.06 exhibits a strong security posture in many areas. The absence of known vulnerabilities in its history is a significant positive indicator, suggesting a history of responsible development and maintenance. Static analysis reveals a small attack surface with no apparent direct entry points like AJAX handlers, REST API routes, or shortcodes that are unprotected. Furthermore, SQL queries are all properly prepared, mitigating common injection risks. The high percentage of properly escaped output is also commendable, reducing the likelihood of cross-site scripting vulnerabilities.
However, there are notable areas for concern. The presence of two flows with unsanitized paths in the taint analysis, even without critical or high severity, warrants attention. This indicates potential for vulnerabilities if these paths are exploited. The absence of nonce checks and capability checks across the board is a significant weakness. This means that any functionality, if discovered, could potentially be triggered by unauthenticated or unauthorized users. The single file operation and single external HTTP request, while not inherently dangerous, are potential vectors that could be exploited if not handled with extreme care and robust validation.
In conclusion, while the plugin benefits from a clean vulnerability history and good practices in SQL and output handling, the lack of essential security checks like nonces and capability checks, coupled with unsanitized paths, presents a tangible risk. The small attack surface is a mitigating factor, but the identified weaknesses could be exploited, especially if new entry points are discovered or existing ones are leveraged. Developers should prioritize addressing the unsanitized paths and implementing appropriate authorization and nonce checks.
Key Concerns
- Unsanitized paths in taint analysis
- Missing nonce checks
- Missing capability checks
- File operations without clear context
- External HTTP requests without clear context
Contact Form 7 – Campaign Monitor Addon Security Vulnerabilities
Contact Form 7 – Campaign Monitor Addon Code Analysis
Output Escaping
Data Flow Analysis
Contact Form 7 – Campaign Monitor Addon Attack Surface
WordPress Hooks 6
Maintenance & Trust
Contact Form 7 – Campaign Monitor Addon Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 – Campaign Monitor Addon Alternatives
Connect Contact Form 7 and AWeber
integrate-contact-form-7-and-aweber
Integrate AWeber mailing lists with Contact Form 7. Automatically add form subscribers to your AWeber lists.
Contact Form 7 SendInBlue Opt-in Checkbox
cf7-sendinblue-opt-in-checkbox
WordPress plugin to add a SendinBlue Opt-in checkbox for Contact Form 7
Email Blaster Newsletter Signup Form
email-blaster-newsletter-signup-form
Email subscribe forms for your website. Send HTML email marketing (newsletters). GDPR compliant, UK based email marketing and email automation.
Campaign Monitor Add-On for FormCraft
campaign-monitor-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your Campaign Monitor list.
Hostinger Reach – AI-Powered Email Marketing for WordPress
hostinger-reach
Launch and grow your email marketing effortlessly with Hostinger Reach. Collect contacts, sync subscribers, and send emails – all in one, AI powered.
Contact Form 7 – Campaign Monitor Addon Developer Profile
1 plugin · 100 total installs
How We Detect Contact Form 7 – Campaign Monitor Addon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-7-campaignmonitor-addon/scripts.js/wp-content/plugins/contact-form-7-campaignmonitor-addon/scripts.jscontact-form-7-campaignmonitor-addon/scripts.js?ver=HTML / DOM Fingerprints
mail-fieldhalf-lefthalf-rightcampaignmonitor-custom-fieldspseudo-hrid="wpcf7-campaignmonitor-active"name="wpcf7-campaignmonitor[active]"id="wpcf7-campaignmonitor-email"name="wpcf7-campaignmonitor[email]"id="wpcf7-campaignmonitor-name"name="wpcf7-campaignmonitor[name]"+16 moreWPCF7_CM_VERSION