Contact Form 7 – Success Page Redirects Security & Risk Analysis

wordpress.org/plugins/contact-form-7-success-page-redirects

An add-on for Contact Form 7 that provides a straightforward method to redirect visitors to success pages or thank you pages.

10K active installs v1.2.0 PHP + WP 3.8.2+ Updated Nov 28, 2017
cf7contact-formcontact-form-7contact-forms-7redirect
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Contact Form 7 – Success Page Redirects Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 – Success Page Redirects has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin 'contact-form-7-success-page-redirects' v1.2.0 exhibits a generally strong security posture based on the provided static analysis. The complete absence of a discernible attack surface (AJAX handlers, REST API routes, shortcodes, cron events) is a significant positive, indicating minimal entry points for attackers. Furthermore, the lack of dangerous functions, file operations, and external HTTP requests, coupled with 100% of SQL queries utilizing prepared statements and a single nonce check, all suggest a developer conscious of common vulnerabilities. The vulnerability history being entirely clear further reinforces this positive outlook, showing no past or present known security flaws.

However, a critical concern arises from the static analysis revealing that 0% of the total 2 outputs are properly escaped. This means that any data displayed to users, even if originating from trusted sources within the plugin, could potentially be vulnerable to cross-site scripting (XSS) attacks. While the taint analysis showed no unsanitized paths, the lack of output escaping on its own creates a risk. The absence of capability checks on any potential entry points (though none were found) is a minor concern, as it's always best practice to verify user permissions.

In conclusion, the plugin has proactively mitigated many common web application vulnerabilities. The absence of known CVEs and a clean vulnerability history are excellent indicators. The primary weakness lies in the critical lack of output escaping, which, despite the lack of identified taint flows, represents a tangible risk of XSS. The minimal attack surface and secure handling of database interactions are commendable strengths.

Key Concerns

  • No output escaping
Vulnerabilities
None known

Contact Form 7 – Success Page Redirects Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form 7 – Success Page Redirects Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped2 total outputs
Attack Surface

Contact Form 7 – Success Page Redirects Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_noticescf7-success-page-redirects.php:35
filterwpcf7_load_jscf7-success-page-redirects.php:41
actionwpcf7_add_meta_boxescf7-success-page-redirects.php:52
actionwpcf7_editor_panelscf7-success-page-redirects.php:64
actionwpcf7_after_savecf7-success-page-redirects.php:123
actionwpcf7_after_createcf7-success-page-redirects.php:139
actionwpcf7_mail_sentcf7-success-page-redirects.php:155
Maintenance & Trust

Contact Form 7 – Success Page Redirects Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedNov 28, 2017
PHP min version
Downloads97K

Community Trust

Rating84/100
Number of ratings27
Active installs10K
Developer Profile

Contact Form 7 – Success Page Redirects Developer Profile

Ryan Nevius

2 plugins · 10K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 – Success Page Redirects

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
cf7-redirect-settingscf7-redirect-panel
Data Attributes
id="cf7-redirect-settings"id="cf7-redirect-panel"
FAQ

Frequently Asked Questions about Contact Form 7 – Success Page Redirects