Contact Form 7 Referrer Addon Plugin Security & Risk Analysis

wordpress.org/plugins/contact-form-7-referrer-addon

Add useful referrer information to emails sent via any Contact Form 7 contact forms on your Wordpress website. Based on the Enhanced Wordpress Contact …

60 active installs v1.0.0 PHP + WP + Updated Dec 10, 2014
cf7contact-formcontact-form-7referralreferrer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form 7 Referrer Addon Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 Referrer Addon Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "contact-form-7-referrer-addon" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, raw SQL queries, file operations, external HTTP requests, or critical/high severity taint flows is commendable. The plugin also scores well by having no known CVEs, indicating a history of secure development or prompt patching.

However, there is a notable concern regarding output escaping. The static analysis reveals one total output with 0% properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data or data from external sources is directly rendered without proper sanitization. While the attack surface appears to be zero and there are no obvious points of entry for malicious code execution, the lack of output escaping represents a significant weakness that could be exploited.

In conclusion, the plugin benefits from a minimal attack surface and a clean vulnerability history. Nevertheless, the single instance of unescaped output presents a clear and present risk that needs to be addressed to improve the plugin's overall security.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Contact Form 7 Referrer Addon Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form 7 Referrer Addon Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
wpcf7_referrer_promo_message (referrer.php:14)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Contact Form 7 Referrer Addon Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_noticesreferrer.php:47
filterwpcf7_referrer_keywords_queryreferrer.php:69
actioninitreferrer.php:95
filterwpcf7_mail_componentsreferrer.php:158
Maintenance & Trust

Contact Form 7 Referrer Addon Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedDec 10, 2014
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs60
Developer Profile

Contact Form 7 Referrer Addon Plugin Developer Profile

nicholas_tsim

1 plugin · 60 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 Referrer Addon Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
updated
JS Globals
wpcf7_pageswpcf7_referer
FAQ

Frequently Asked Questions about Contact Form 7 Referrer Addon Plugin