Controller Fields for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/controller-fields-for-contact-form-7

Hide or display content in your forms created in Contact Form 7 based on user selections!

50 active installs v2.0.0 PHP 7.4+ WP 5.8+ Updated Dec 2, 2024
conditionalcontact-form-7dynamicinteractiveuser-based
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Controller Fields for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 92/100

Controller Fields for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of controller-fields-for-contact-form-7 v2.0.0 reveals an exceptionally strong security posture. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in zero attack surface and zero unprotected entry points. The code demonstrates excellent security practices with no dangerous functions, all SQL queries utilizing prepared statements, and all output being properly escaped. The absence of file operations, external HTTP requests, and any taint analysis findings further reinforces this positive assessment.

The vulnerability history for this plugin is also clean, with no recorded CVEs. This indicates a consistent and well-maintained security record. While the lack of nonce and capability checks is a point to note, given the absence of any exposed entry points, this weakness does not present an immediate risk in this specific version. The plugin's strengths lie in its minimal attack surface and robust internal code security practices.

In conclusion, controller-fields-for-contact-form-7 v2.0.0 appears to be a highly secure plugin based on the provided static analysis and vulnerability history. The developers have implemented sound security measures, and the lack of any discovered vulnerabilities or exploitable code paths is a significant positive indicator. The absence of specific security mechanisms like nonce and capability checks is overshadowed by the complete lack of exposed functionality that would necessitate them.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

Controller Fields for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Controller Fields for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
59 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped59 total outputs
Attack Surface

Controller Fields for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionwpcf7_initcontroller-fields-for-contact-form-7.php:57
filterau_cf7_cf_controller_shortcode_handlercontroller-fields-for-contact-form-7.php:58
actionplugins_loadedcontroller-fields-for-contact-form-7.php:60
actionwp_enqueue_scriptscontroller-fields-for-contact-form-7.php:311
actionadmin_enqueue_scriptsincludes\admin.php:45
actionwpcf7_admin_initincludes\admin.php:46
Maintenance & Trust

Controller Fields for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 2, 2024
PHP min version7.4
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

Controller Fields for Contact Form 7 Developer Profile

Tessa (they/them), AuRise Creative

5 plugins · 10K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Controller Fields for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/controller-fields-for-contact-form-7/assets/css/cf7-controller-fields.css/wp-content/plugins/controller-fields-for-contact-form-7/assets/js/cf7-controller-fields.js
Script Paths
/wp-content/plugins/controller-fields-for-contact-form-7/assets/js/cf7-controller-fields.js
Version Parameters
controller-fields-for-contact-form-7/assets/css/cf7-controller-fields.css?ver=controller-fields-for-contact-form-7/assets/js/cf7-controller-fields.js?ver=

HTML / DOM Fingerprints

CSS Classes
au-cf7-controllerwpcf7-list-itemwpcf7-list-item-firstwpcf7-list-item-lastwpcf7-exclusive-checkbox
Data Attributes
data-collapsedata-id
JS Globals
cf7ControllerFields
Shortcode Output
<span class="wpcf7-list-item<span class="wpcf7-list-item-exclusivewpcf7-list-item-firstwpcf7-list-item-last
FAQ

Frequently Asked Questions about Controller Fields for Contact Form 7