Contact Form 7 Modules Security & Risk Analysis

wordpress.org/plugins/contact-form-7-modules

Contact Form 7 - Add useful modules such as hidden fields and "send all fields" to the Contact Form 7 plugin

5K active installs v2.0.2 PHP + WP 2.8+ Updated Nov 28, 2017
all-fieldscf7contact-form-7contact-forms-7hidden-fields
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form 7 Modules Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 Modules has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "contact-form-7-modules" v2.0.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of identified dangerous functions, the exclusive use of prepared statements for SQL queries, and a high percentage of properly escaped output suggest good development practices. Furthermore, the lack of file operations, external HTTP requests, and the absence of reported vulnerabilities in its history contribute to a generally positive security assessment. The plugin also demonstrates a minimal attack surface with no apparent unprotected entry points like AJAX handlers or REST API routes, and no shortcodes or cron events were detected. This indicates a well-contained and securely coded plugin.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Contact Form 7 Modules Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form 7 Modules Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

93% escaped29 total outputs
Attack Surface

Contact Form 7 Modules Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedhidden.php:15
actionadmin_noticeshidden.php:30
actionadmin_enqueue_scriptshidden.php:31
filterwpcf7_form_elementshidden.php:58
actionadmin_inithidden.php:269
filterwpcf7_mail_componentssend-all-fields.php:15
filterwpcf7_collect_mail_tagssend-all-fields.php:99
Maintenance & Trust

Contact Form 7 Modules Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedNov 28, 2017
PHP min version
Downloads248K

Community Trust

Rating74/100
Number of ratings22
Active installs5K
Developer Profile

Contact Form 7 Modules Developer Profile

Zack Katz

23 plugins · 14K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 Modules

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contact-form-7-modules/css/hidden.css/wp-content/plugins/contact-form-7-modules/js/hidden.js
Script Paths
/wp-content/plugins/contact-form-7-modules/js/hidden.js

HTML / DOM Fingerprints

CSS Classes
wpcf7-hidden
HTML Comments
<!-- CF7 Modules --><!-- End CF7 Modules -->
Data Attributes
wpcf7-form-control-wrap
Shortcode Output
<input type="hidden"id="wpcf7-hidden-name="hidden-
FAQ

Frequently Asked Questions about Contact Form 7 Modules