Contact Form 7 To WordPress Post Security & Risk Analysis

wordpress.org/plugins/contact-form-to-wp-posts

Extend Contact Form 7 and save form entries into WordPress posts.

50 active installs v0.2 PHP + WP 3.9+ Updated Nov 2, 2018
cf7contact-form-7database-formsave-entriessubmissions
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form 7 To WordPress Post Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 To WordPress Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "contact-form-to-wp-posts" plugin version 0.2 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified AJAX handlers, REST API routes, shortcodes, cron events, or file operations significantly limits the plugin's attack surface. Furthermore, the code signals indicate a robust implementation with no dangerous functions, all SQL queries using prepared statements, and all output being properly escaped. The presence of nonce checks further bolsters its security by protecting against CSRF attacks.

The vulnerability history reinforces this positive assessment, with zero known CVEs and no recorded vulnerabilities of any severity. This suggests a history of secure development and maintenance, or that the plugin is relatively new and has not yet been targeted or discovered to have flaws. The taint analysis also shows no identified flows with unsanitized paths, indicating a lack of exploitable data injection vulnerabilities.

Overall, this plugin appears to be well-secured and follows good WordPress development practices. The strengths lie in its minimal attack surface, diligent use of prepared statements and output escaping, and the inclusion of nonce checks. The primary weakness, if any can be inferred, is the complete absence of capability checks, which could be a concern if the plugin were to expand its functionality and handle sensitive operations. However, given the current scope and lack of identified entry points, this is a minor concern.

Vulnerabilities
None known

Contact Form 7 To WordPress Post Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Contact Form 7 To WordPress Post Release Timeline

v0.2Current
v0.1
Code Analysis
Analyzed Apr 16, 2026

Contact Form 7 To WordPress Post Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
14 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped14 total outputs
Attack Surface

Contact Form 7 To WordPress Post Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionplugins_loadedcf7-to-wp.php:41
actioninitincludes/class-cf7_to_wp.php:81
actioninitincludes/class-cf7_to_wp.php:89
filteradd_menu_classesincludes/class-cf7_to_wp.php:90
filterpost_row_actionsincludes/class-cf7_to_wp.php:91
actionadmin_initincludes/class-cf7_to_wp.php:92
filterwpcf7_editor_panelsincludes/class-cf7_to_wp.php:95
actionwpcf7_after_saveincludes/class-cf7_to_wp.php:96
actionwpcf7_mail_sentincludes/class-cf7_to_wp.php:97
actionwpcf7_mail_failedincludes/class-cf7_to_wp.php:98
Maintenance & Trust

Contact Form 7 To WordPress Post Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 2, 2018
PHP min version
Downloads4K

Community Trust

Rating66/100
Number of ratings3
Active installs50
Developer Profile

Contact Form 7 To WordPress Post Developer Profile

Pierre Saïkali

3 plugins · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 To WordPress Post

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contact-form-to-wp-posts/assets/css/style.css/wp-content/plugins/contact-form-to-wp-posts/assets/js/script.js
Script Paths
/wp-content/plugins/contact-form-to-wp-posts/assets/js/script.js
Version Parameters
contact-form-to-wp-posts/assets/css/style.css?ver=contact-form-to-wp-posts/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
pseudo-hr
Data Attributes
name="wpcf7-cf7towp-active"name="wpcf7-cf7towp-title"name="wpcf7-cf7towp-content"
FAQ

Frequently Asked Questions about Contact Form 7 To WordPress Post