
Controls for Contact Form 7 (Redirects, Analytics & Tracking) Security & Risk Analysis
wordpress.org/plugins/contact-form-7-extrasAnalytics, tracking, redirects and storage for Contact Form 7.
Is Controls for Contact Form 7 (Redirects, Analytics & Tracking) Safe to Use in 2026?
Generally Safe
Score 92/100Controls for Contact Form 7 (Redirects, Analytics & Tracking) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "contact-form-7-extras" v0.10.0 reveals a strong security posture with no identified critical vulnerabilities. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the plugin demonstrates good practice in output escaping, with 94% of outputs properly escaped, and it includes one capability check, indicating an awareness of authorization. The zero taint flows and zero known CVEs further contribute to a positive security assessment.
However, a significant concern is the complete lack of nonce checks. While the plugin has a small attack surface with zero entry points and unprotected elements, the absence of nonce checks on potential future entry points or any client-server interaction, even if currently not exploited, represents a potential weakness. This could be exploited if new AJAX handlers, REST API routes, or other interaction methods were added without proper security considerations. The vulnerability history shows no past issues, which is a strong positive, but it doesn't negate the need for robust security mechanisms like nonce checks.
In conclusion, "contact-form-7-extras" v0.10.0 exhibits a generally secure design based on the provided data, with a clean code base and no recorded vulnerabilities. Its strengths lie in its lack of dangerous functions and well-escaped output. The primary area for improvement and a potential risk is the complete absence of nonce checks, which should be addressed to ensure comprehensive security against potential future threats and evolving WordPress security standards.
Key Concerns
- Missing nonce checks
Controls for Contact Form 7 (Redirects, Analytics & Tracking) Security Vulnerabilities
Controls for Contact Form 7 (Redirects, Analytics & Tracking) Code Analysis
Output Escaping
Controls for Contact Form 7 (Redirects, Analytics & Tracking) Attack Surface
WordPress Hooks 17
Maintenance & Trust
Controls for Contact Form 7 (Redirects, Analytics & Tracking) Maintenance & Trust
Maintenance Signals
Community Trust
Controls for Contact Form 7 (Redirects, Analytics & Tracking) Alternatives
DataLayer for GTM and Matomo
datalayer
Add contextual information to dataLayer for GTM and MTM
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
Insert Headers And Footers
wp-headers-and-footers
Include inline javascript, stylesheets, CSS code or anything you want in Header and Footer areas of your WordPress with ease.
Connect Matomo – Analytics Dashboard for WordPress
wp-piwik
Adds Matomo (former Piwik) statistics to your WordPress dashboard and is also able to add the Matomo Tracking Code to your blog.
Pixel Manager for WooCommerce – Conversion Tracking, Google Ads, GA4, TikTok, Dynamic Remarketing
woocommerce-google-adwords-conversion-tracking-tag
Conversion tracking for WooCommerce. Google Ads, GA4, Meta/Facebook Pixel, TikTok & more. Recover 30% more conversions with server-side tracking!
Controls for Contact Form 7 (Redirects, Analytics & Tracking) Developer Profile
5 plugins · 50K total installs
How We Detect Controls for Contact Form 7 (Redirects, Analytics & Tracking)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-7-extras/assets/css/admin.css/wp-content/plugins/contact-form-7-extras/assets/css/frontend.css/wp-content/plugins/contact-form-7-extras/assets/js/backend.js/wp-content/plugins/contact-form-7-extras/assets/js/frontend.js/wp-content/plugins/contact-form-7-extras/assets/js/backend.js/wp-content/plugins/contact-form-7-extras/assets/js/frontend.jscontact-form-7-extras/assets/css/admin.css?ver=contact-form-7-extras/assets/css/frontend.css?ver=contact-form-7-extras/assets/js/backend.js?ver=contact-form-7-extras/assets/js/frontend.js?ver=HTML / DOM Fingerprints
data-toggle-on