
Accept Elavon Payments using Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/contact-form-7-elavon-convergeIntegrate elavon payment gateway for making your payments through Contact Form 7.
Is Accept Elavon Payments using Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100Accept Elavon Payments using Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "contact-form-7-elavon-converge" plugin v3.5 exhibits several significant security concerns, primarily due to a lack of proper access control and data sanitization on its AJAX endpoints. With a total of 8 AJAX handlers, all of which are unprotected, there is a substantial attack surface that could be exploited by unauthenticated users. Furthermore, the presence of SQL queries that are not prepared statements indicates a risk of SQL injection vulnerabilities. While the taint analysis did not reveal critical or high-severity issues, the fact that all analyzed flows had unsanitized paths is concerning, especially in conjunction with the unprotected entry points.
The plugin's vulnerability history is notably clean, with no recorded CVEs. This is a positive indicator and suggests that the developers may have a good track record or that the plugin hasn't been a significant target for exploitation. However, this absence of past vulnerabilities should not lead to complacency, especially given the current findings of insecure coding practices in the static analysis. The lack of nonce checks and capability checks on the AJAX handlers are critical omissions that directly expose the plugin to potential Cross-Site Request Forgery (CSRF) and privilege escalation attacks.
In conclusion, while the plugin has a clean vulnerability history, its current version (v3.5) presents a high risk due to unprotected AJAX endpoints, potential SQL injection vulnerabilities, and the absence of essential security checks like nonces and capability checks. The high number of unprotected entry points is a primary area of concern, and significant improvements are needed in access control and input validation to secure this plugin.
Key Concerns
- All 8 AJAX handlers lack authentication checks
- SQL queries present without prepared statements
- Unsanitized paths in taint analysis flows
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
- Low output escaping percentage
Accept Elavon Payments using Contact Form 7 Security Vulnerabilities
Accept Elavon Payments using Contact Form 7 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Accept Elavon Payments using Contact Form 7 Attack Surface
AJAX Handlers 8
WordPress Hooks 15
Maintenance & Trust
Accept Elavon Payments using Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Accept Elavon Payments using Contact Form 7 Alternatives
Contact Form 7 – Success Page Redirects
contact-form-7-success-page-redirects
An add-on for Contact Form 7 that provides a straightforward method to redirect visitors to success pages or thank you pages.
Contact Form 7 Modules
contact-form-7-modules
Contact Form 7 - Add useful modules such as hidden fields and "send all fields" to the Contact Form 7 plugin
Contact Forms 7 Digital Signature Add-On
digital-signature-contact-form-7-addon
Instantly produce a legally enforceable & court recognized contract from a Contact Form 7 submission. Legal contracts. UETA/ESIGN Compliant.
Contact Form 7 – InfusionSoft Add-on
contact-form-7-infusionsoft-add-on
An add-on for Contact Form 7 that provides a way to capture leads, tag customers, and send contact form data to InfusionSoft.
Accept Authorize.NET Payments Using Contact Form 7
accept-authorize-net-payments-using-contact-form-7
Contact Form 7 - Integrate Authorize.Net payment gateway for making your payments through Contact Form 7.
Accept Elavon Payments using Contact Form 7 Developer Profile
18 plugins · 7K total installs
How We Detect Accept Elavon Payments using Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-7-elavon-converge-payment-gateway/css/elavon-extension.csshttps://js.elavon.com/v2/HTML / DOM Fingerprints
elavon-settings<!-- A base module for elavon express checkout form that allows to submit payment from Contact Form 7. -->name="use_elavon"name="amounts"name="transaction_type_elavon"name="merchant_id_elavon"name="user_id_elavon"name="pin_elavon"+1 morejQuery[elavon]