
Country & Phone Field Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/country-phone-field-contact-form-7Add country drop down with flags and phone number with country phone extension fields in contact form 7.
Is Country & Phone Field Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100Country & Phone Field Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'country-phone-field-contact-form-7' v2.6.5 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs and a clean vulnerability history are significant strengths, indicating a history of robust security practices. The code analysis reveals a minimal attack surface with no registered AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the plugin correctly utilizes prepared statements for all SQL queries and boasts a high percentage of properly escaped output, mitigating common vulnerabilities like SQL injection and XSS. The presence of capability checks and the limited external HTTP request are also positive signs.
However, there are two concerning signals from the taint analysis: two flows with unsanitized paths. While no critical or high severity issues were identified here, unsanitized paths can still lead to vulnerabilities if not handled carefully within the plugin's logic. The lack of nonce checks, though not explicitly linked to an unprotected entry point in this analysis, is a general security best practice for functions that perform sensitive operations. The plugin's strengths lie in its minimal attack surface and diligent use of database and output escaping. The primary area for improvement, albeit with no critical findings in this instance, is the handling of unsanitized paths and the consideration of nonce checks where applicable.
Key Concerns
- Taint flow with unsanitized paths found
- Taint flow with unsanitized paths found
- No nonce checks detected
Country & Phone Field Contact Form 7 Security Vulnerabilities
Country & Phone Field Contact Form 7 Release Timeline
Country & Phone Field Contact Form 7 Code Analysis
Output Escaping
Data Flow Analysis
Country & Phone Field Contact Form 7 Attack Surface
WordPress Hooks 15
Maintenance & Trust
Country & Phone Field Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Country & Phone Field Contact Form 7 Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 – Dynamic Text Extension
contact-form-7-dynamic-text-extension
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
Country & Phone Field Contact Form 7 Developer Profile
2 plugins · 40K total installs
How We Detect Country & Phone Field Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/country-phone-field-contact-form-7/assets/css/intlTelInput.min.css/wp-content/plugins/country-phone-field-contact-form-7/assets/css/countrySelect.min.css/wp-content/plugins/country-phone-field-contact-form-7/assets/js/intlTelInput.min.js/wp-content/plugins/country-phone-field-contact-form-7/assets/js/countrySelect.min.js/wp-content/plugins/country-phone-field-contact-form-7/assets/js/intlTelInput.min.js/wp-content/plugins/country-phone-field-contact-form-7/assets/js/countrySelect.min.jsHTML / DOM Fingerprints
wpcf7-countrytextwpcf7-phonetextdata-country-codedata-country-namedata-dial-codenbcpf