Contact Form 7 – SalesKing CRM Addon Security & Risk Analysis

wordpress.org/plugins/contact-form-7-salesking-crm-addon

Get your Contact Form 7 data straight into SalesKing CRM.

10 active installs v1.1.0 PHP + WP 3.2+ Updated Apr 14, 2014
contact-form-7crmgermanleadssalesking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form 7 – SalesKing CRM Addon Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 – SalesKing CRM Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The plugin "contact-form-7-salesking-crm-addon" v1.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and properly escaping a high percentage of its outputs. The absence of file operations and external HTTP requests, along with no known vulnerabilities in its history, are also strong indicators of careful development. However, significant concerns arise from its attack surface analysis. The presence of one unprotected AJAX handler is a critical weakness, as it represents a direct entry point for potential malicious activity without any authentication or authorization checks. This lack of protection on an AJAX endpoint could be exploited to trigger unintended actions or expose sensitive information.

While the taint analysis did not reveal critical or high-severity issues, the presence of two flows with unsanitized paths warrants attention. Coupled with the single unprotected AJAX handler, this suggests that even though direct critical vulnerabilities aren't immediately apparent from the static analysis, the pathway to exploitation exists. The plugin's vulnerability history being completely clean is a good sign, but it does not negate the risks presented by the current code's weaknesses, particularly the unprotected AJAX endpoint. Overall, the plugin has some strengths in its coding practices, but the unprotected AJAX handler significantly elevates its risk profile.

Key Concerns

  • Unprotected AJAX handler
  • Flows with unsanitized paths (2)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Contact Form 7 – SalesKing CRM Addon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Contact Form 7 – SalesKing CRM Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
43 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped47 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
save_form (models\sk_cf_admin.class.php:95)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Contact Form 7 – SalesKing CRM Addon Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_sk_login_testmodels\sk_cf_admin.class.php:24
WordPress Hooks 8
actioninitmodels\sk_cf.class.php:4
actionwpcf7_before_send_mailmodels\sk_cf.class.php:15
actionadmin_initmodels\sk_cf_admin.class.php:7
actionwpcf7_admin_noticesmodels\sk_cf_admin.class.php:19
actionwpcf7_admin_after_mail_2models\sk_cf_admin.class.php:20
actionwpcf7_after_savemodels\sk_cf_admin.class.php:21
actionadmin_print_scriptsmodels\sk_cf_admin.class.php:22
filterplugin_action_linksmodels\sk_cf_admin.class.php:23
Maintenance & Trust

Contact Form 7 – SalesKing CRM Addon Maintenance & Trust

Maintenance Signals

WordPress version tested3.5.2
Last updatedApr 14, 2014
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Contact Form 7 – SalesKing CRM Addon Developer Profile

killer-g

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 – SalesKing CRM Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contact-form-7-salesking-crm-addon/assets/js/admin.js
Version Parameters
contact-form-7-salesking-crm-addon/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpcf7-sk-active
Data Attributes
name="wpcf7-sk[active]"id="wpcf7-sk-active"name="wpcf7-sk[email]"id="wpcf7-sk-email"name="wpcf7-sk[last_name]"id="wpcf7-sk-last_name"+8 more
JS Globals
WPCF7_SK_VERSION
REST Endpoints
/wp-json/wpcf7-sk/v1/test
FAQ

Frequently Asked Questions about Contact Form 7 – SalesKing CRM Addon