Contact Form 7 : Wysiwyg Field Security & Risk Analysis

wordpress.org/plugins/contact-form-7-wysiwyg-field

Add wysiwyg fields to the popular Contact Form 7 plugin.

20 active installs v1.5 PHP + WP 3.8.1+ Updated Sep 16, 2014
contact-form-7editor-fieldfieldform-fieldwisiwyg
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form 7 : Wysiwyg Field Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 : Wysiwyg Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The static analysis of "contact-form-7-wysiwyg-field" v1.5 indicates a strong security posture based on the provided metrics. The plugin exhibits no identified attack surface through AJAX, REST API, shortcodes, or cron events, and importantly, all entry points appear to be protected. Furthermore, the code employs good practices by utilizing prepared statements for all SQL queries and ensuring all output is properly escaped, with no dangerous functions, file operations, or external HTTP requests observed. The absence of any recorded vulnerabilities, critical or otherwise, in its history also contributes positively to its security standing.

Vulnerabilities
None known

Contact Form 7 : Wysiwyg Field Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Contact Form 7 : Wysiwyg Field Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped24 total outputs
Attack Surface

Contact Form 7 : Wysiwyg Field Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitwysiwyg.php:17
filterwpcf7_mail_componentswysiwyg.php:20
filterwpcf7_validate_wysiwyg*wysiwyg.php:101
actionadmin_initwysiwyg.php:124
Maintenance & Trust

Contact Form 7 : Wysiwyg Field Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedSep 16, 2014
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Contact Form 7 : Wysiwyg Field Developer Profile

Nicolas GRILLET

3 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 : Wysiwyg Field

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contact-form-7-wysiwyg-field/contact-form-7-wysiwyg-field.php
Script Paths
jquery

HTML / DOM Fingerprints

CSS Classes
wpcf7-form-control-wrapwpcf7_form_novalidate
Data Attributes
data-editor-id
JS Globals
tinyMCE
Shortcode Output
<span class="wpcf7-form-control-wrap<script type="text/javascript">
FAQ

Frequently Asked Questions about Contact Form 7 : Wysiwyg Field