contact form 7 pdf extension Security & Risk Analysis

wordpress.org/plugins/contact-form-pdf-extension

This plugin work with the contact form 7

30 active installs v1.2 PHP + WP 3.0.1+ Updated Jul 15, 2023
contact-form-7-mail-pdfcontact-form-7-pdfcontact-form-7-pdf-extension
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is contact form 7 pdf extension Safe to Use in 2026?

Generally Safe

Score 85/100

contact form 7 pdf extension has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "contact-form-pdf-extension" plugin v1.2 exhibits a generally positive security posture based on the provided static analysis. The complete absence of identified dangerous functions, external HTTP requests, and SQL queries executed without prepared statements are strong indicators of good coding practices. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of stable and secure releases. The lack of any taint analysis findings, even with 0 flows analyzed, suggests that if any flows exist, they are likely sanitized.

However, there are significant areas for concern. The most glaring issue is the complete absence of any nonces or capability checks across all identified entry points. This indicates a critical oversight in input validation and authorization, making any potential vulnerabilities that might arise from other parts of the code much easier to exploit. While the current attack surface is reported as 0 unprotected entry points, this is directly undermined by the lack of security measures. The output escaping rate of 43% is also a significant weakness, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities, especially when combined with the lack of nonces and capability checks. The extensive file operations (84) also warrant scrutiny, as they could be a vector for insecure file handling if not properly secured.

In conclusion, while the plugin benefits from a clean record and good practices in areas like SQL and function usage, the severe lack of nonce checks, capability checks, and inadequate output escaping presents a substantial risk. The plugin is highly susceptible to various attacks, particularly XSS and unauthorized actions, due to these critical omissions. The absence of known vulnerabilities is positive but does not mitigate the inherent risks in the current code structure.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
  • Low output escaping rate (43%)
  • High number of file operations without explicit security checks mentioned
Vulnerabilities
None known

contact form 7 pdf extension Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

contact form 7 pdf extension Release Timeline

v1.2.0
Code Analysis
Analyzed Mar 16, 2026

contact form 7 pdf extension Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
84
External Requests
0
Bundled Libraries
0

Output Escaping

43% escaped28 total outputs
Attack Surface

contact form 7 pdf extension Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menucontact-form-7-pdf-extension.php:16
actionwpcf7_before_send_mailcontact-form-7-pdf-extension.php:123
actionadmin_print_scriptscontact-form-7-pdf-extension.php:205
actionadmin_menutrunk\contact-form-7-pdf-extension.php:16
actionwpcf7_before_send_mailtrunk\contact-form-7-pdf-extension.php:123
actionadmin_print_scriptstrunk\contact-form-7-pdf-extension.php:205
Maintenance & Trust

contact form 7 pdf extension Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 15, 2023
PHP min version
Downloads7K

Community Trust

Rating80/100
Number of ratings5
Active installs30
Developer Profile

contact form 7 pdf extension Developer Profile

AnjitVishwakarma

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect contact form 7 pdf extension

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contact-form-pdf-extension/pdflib/html2fpdf.php

HTML / DOM Fingerprints

CSS Classes
form-groupform-table
Data Attributes
id="cnf_form"name="cnf_frm_id"onchange="change_form(this.value);"
JS Globals
window.location.href
Shortcode Output
[contact-form-7[cf7-form[gravityform
FAQ

Frequently Asked Questions about contact form 7 pdf extension