
Contact Form 7 – InfusionSoft Add-on Security & Risk Analysis
wordpress.org/plugins/contact-form-7-infusionsoft-add-onAn add-on for Contact Form 7 that provides a way to capture leads, tag customers, and send contact form data to InfusionSoft.
Is Contact Form 7 – InfusionSoft Add-on Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form 7 – InfusionSoft Add-on has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "contact-form-7-infusionsoft-add-on" v1.2.2 exhibits a generally strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, and shortcodes, as well as no cron events, significantly reduces the attack surface. Furthermore, the code demonstrates good practices by utilizing prepared statements for all SQL queries and including nonce checks. The lack of any known vulnerabilities or CVEs in its history is a positive indicator of its past security development. However, a notable concern is the low percentage of properly escaped output (27%), which suggests a risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis did not reveal critical or high severity issues, the presence of unsanitized paths in the two analyzed flows warrants attention. The single file operation is not inherently a risk without further context, but it's an area to be mindful of. Overall, the plugin has a solid foundation but requires improvement in output sanitization to mitigate potential XSS risks.
Key Concerns
- Low percentage of properly escaped output
- Taint analysis shows unsanitized paths
Contact Form 7 – InfusionSoft Add-on Security Vulnerabilities
Contact Form 7 – InfusionSoft Add-on Code Analysis
Output Escaping
Data Flow Analysis
Contact Form 7 – InfusionSoft Add-on Attack Surface
WordPress Hooks 9
Maintenance & Trust
Contact Form 7 – InfusionSoft Add-on Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 – InfusionSoft Add-on Alternatives
Contact Form 7 – Success Page Redirects
contact-form-7-success-page-redirects
An add-on for Contact Form 7 that provides a straightforward method to redirect visitors to success pages or thank you pages.
Contact Form 7 Modules
contact-form-7-modules
Contact Form 7 - Add useful modules such as hidden fields and "send all fields" to the Contact Form 7 plugin
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Advanced Contact form 7 DB
advanced-cf7-db
Save all contact form 7 form submitted data to the database, View, Ordering, Change field labels and Import/Export data using CSV.
Contact Form 7 – InfusionSoft Add-on Developer Profile
2 plugins · 10K total installs
How We Detect Contact Form 7 – InfusionSoft Add-on
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-7-infusionsoft-add-on/cf7-infusionsoft-scripts.js/wp-content/plugins/contact-form-7-infusionsoft-add-on/cf7-infusionsoft-scripts.jsHTML / DOM Fingerprints
wpcf7-tg-pane-infusionsoftcf7_infusionsoft_addon_metaboxes_nonceinfusionsoft-emailinfusionsoft-first-nameinfusionsoft-last-nameinfusionsoft-companyinfusionsoft-phone+2 morecf7_infusionsoft_scripts