
contact form 7 pdf extension Security & Risk Analysis
wordpress.org/plugins/contact-form-pdf-extensionThis plugin work with the contact form 7
Is contact form 7 pdf extension Safe to Use in 2026?
Generally Safe
Score 85/100contact form 7 pdf extension has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "contact-form-pdf-extension" plugin v1.2 exhibits a generally positive security posture based on the provided static analysis. The complete absence of identified dangerous functions, external HTTP requests, and SQL queries executed without prepared statements are strong indicators of good coding practices. Furthermore, the plugin has no recorded vulnerability history, suggesting a history of stable and secure releases. The lack of any taint analysis findings, even with 0 flows analyzed, suggests that if any flows exist, they are likely sanitized.
However, there are significant areas for concern. The most glaring issue is the complete absence of any nonces or capability checks across all identified entry points. This indicates a critical oversight in input validation and authorization, making any potential vulnerabilities that might arise from other parts of the code much easier to exploit. While the current attack surface is reported as 0 unprotected entry points, this is directly undermined by the lack of security measures. The output escaping rate of 43% is also a significant weakness, indicating a high likelihood of cross-site scripting (XSS) vulnerabilities, especially when combined with the lack of nonces and capability checks. The extensive file operations (84) also warrant scrutiny, as they could be a vector for insecure file handling if not properly secured.
In conclusion, while the plugin benefits from a clean record and good practices in areas like SQL and function usage, the severe lack of nonce checks, capability checks, and inadequate output escaping presents a substantial risk. The plugin is highly susceptible to various attacks, particularly XSS and unauthorized actions, due to these critical omissions. The absence of known vulnerabilities is positive but does not mitigate the inherent risks in the current code structure.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
- Low output escaping rate (43%)
- High number of file operations without explicit security checks mentioned
contact form 7 pdf extension Security Vulnerabilities
contact form 7 pdf extension Release Timeline
contact form 7 pdf extension Code Analysis
Output Escaping
contact form 7 pdf extension Attack Surface
WordPress Hooks 6
Maintenance & Trust
contact form 7 pdf extension Maintenance & Trust
Maintenance Signals
Community Trust
contact form 7 pdf extension Developer Profile
2 plugins · 40 total installs
How We Detect contact form 7 pdf extension
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-pdf-extension/pdflib/html2fpdf.phpHTML / DOM Fingerprints
form-groupform-tableid="cnf_form"name="cnf_frm_id"onchange="change_form(this.value);"window.location.href[contact-form-7[cf7-form[gravityform