
Contact Form to Any API Security & Risk Analysis
wordpress.org/plugins/contact-form-to-any-apiSend Contact Form 7 submissions to any API, Webhook or CRM - quick setup, flexible payloads, endpoints and authentication.
Is Contact Form to Any API Safe to Use in 2026?
Generally Safe
Score 93/100Contact Form to Any API has a strong security track record. Known vulnerabilities have been patched promptly.
The 'contact-form-to-any-api' plugin exhibits a mixed security posture. While it demonstrates good practices such as a high percentage of SQL prepared statements and properly escaped output, significant concerns arise from its attack surface and past vulnerability history. The presence of four AJAX handlers without authorization checks is a major weakness, creating direct entry points for attackers. This is further compounded by taint analysis revealing three high-severity flows, indicating potential for attackers to influence the application's behavior with unsanitized input.
The plugin's vulnerability history, with four known CVEs including one critical and two high severity, is a strong indicator of recurring security flaws. The common vulnerability types listed (XSS, SQL Injection, Missing Authorization) align with the identified risks in the static analysis. The recent vulnerability in September 2024 suggests ongoing security challenges. Despite the otherwise robust coding practices, the combination of an unprotected attack surface and a history of critical vulnerabilities necessitates caution.
In conclusion, while the plugin has strengths in its use of prepared statements and output escaping, the unprotected AJAX endpoints and a concerning history of severe vulnerabilities represent significant risks. The plugin requires careful monitoring and prompt updates to address potential exploits.
Key Concerns
- Unprotected AJAX handlers
- High severity taint flows
- Previous critical vulnerability
- Previous high severity vulnerabilities (2)
- Bundled library (Select2)
Contact Form to Any API Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Contact Form to Any API <= 1.2.4 - Unauthenticated Stored Cross-Site Scripting via Contact Form
Contact Form to Any API <= 1.1.8 - Authenticated (Subscriber+) SQL Injection
Contact Form to Any API <= 1.1.6 - Missing Authorization via delete_cf7_records()
Contact Form to Any API <= 1.1.2 - Authenticated (Administrator+) SQL Injection via 'form_id'
Contact Form to Any API Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Contact Form to Any API Attack Surface
AJAX Handlers 4
WordPress Hooks 17
Maintenance & Trust
Contact Form to Any API Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form to Any API Alternatives
WP Dynamics CRM for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms
cf7-dynamics-crm
Send Contact Form 7, WPForms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to dynamics crm Online.
Webhook Configuration CF7
webhook-configuration-cf7
Use Contact Form 7 as a trigger to any webhook!
Kainoto Webhook for Contact Form 7
kainoto-webhook-for-contact-form-7
Send Contact Form 7 submissions to webhook URLs without waiting for response. Perfect for integrations with external services.
RT Webhook for Contact Form 7
rt-webhook-for-contact-form-7
An advanced webhook integration for Contact Form 7 with field mapping, conditional logic, and custom headers.
Cubo CRM
cubo-crm
Seamlessly integrate Contact Form 7 with Cubo CRM to manage deals and automate workflows directly from your WordPress site.
Contact Form to Any API Developer Profile
10 plugins · 11K total installs
How We Detect Contact Form to Any API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-to-any-api/css/cf7-to-any-api-admin.css/wp-content/plugins/contact-form-to-any-api/js/cf7-to-any-api-admin.jscontact-form-to-any-api/css/cf7-to-any-api-admin.css?ver=contact-form-to-any-api/js/cf7-to-any-api-admin.js?ver=HTML / DOM Fingerprints
cf7anyapi-notice-barcf7anyapi-close-btncf7_to_any_api_site_urlcf7_to_any_api_ajax_urlcf7_to_any_api_ajax_object