
Contact Form 7 Get and Show Parameter from URL Security & Risk Analysis
wordpress.org/plugins/contact-form-7-get-and-show-parameter-from-urlGet or show parameters from the URL directly within the Contact Form 7 plugin
Is Contact Form 7 Get and Show Parameter from URL Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form 7 Get and Show Parameter from URL has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "contact-form-7-get-and-show-parameter-from-url" v0.9.7 reveals a positive security posture with several good practices observed. Notably, the plugin demonstrates a commitment to secure coding by using prepared statements for all SQL queries and ensuring all output is properly escaped, which significantly mitigates common web vulnerabilities like SQL injection and cross-site scripting. The absence of direct file operations, external HTTP requests, and dangerous function usage further strengthens its security. The plugin also presents a minimal attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without proper authentication or permission checks. This indicates a well-contained and thoughtfully designed plugin.
Furthermore, the plugin's vulnerability history is exceptionally clean, with no recorded CVEs, critical or high severity vulnerabilities, or any historical issues. This lack of past vulnerabilities suggests a proactive approach to security by the developers or that the plugin's functionality is inherently less prone to complex exploit chains. The absence of any taint analysis findings further reinforces the current assessment of low risk. In conclusion, based on the provided data, this plugin appears to be secure. The developers have implemented fundamental security best practices, and there is no evidence of exploitable weaknesses. While the lack of explicit capability checks on entry points might be a theoretical concern in extremely complex scenarios, the overall lack of attack surface and the absence of historical issues make this a very low-risk plugin.
Contact Form 7 Get and Show Parameter from URL Security Vulnerabilities
Contact Form 7 Get and Show Parameter from URL Code Analysis
Output Escaping
Contact Form 7 Get and Show Parameter from URL Attack Surface
WordPress Hooks 1
Maintenance & Trust
Contact Form 7 Get and Show Parameter from URL Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 Get and Show Parameter from URL Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 – Dynamic Text Extension
contact-form-7-dynamic-text-extension
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
Contact Form 7 Get and Show Parameter from URL Developer Profile
1 plugin · 900 total installs
How We Detect Contact Form 7 Get and Show Parameter from URL
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<input type="hidden" name="" value="