
Country State City Dropdown CF7 Security & Risk Analysis
wordpress.org/plugins/country-state-city-auto-dropdownAdd country state city dropdown CF7 in contact form 7 plugin. In PRO you can use these features on any type of form.
Is Country State City Dropdown CF7 Safe to Use in 2026?
Generally Safe
Score 96/100Country State City Dropdown CF7 has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin "country-state-city-auto-dropdown" version 2.7.6 exhibits a generally good security posture with several strengths. The static analysis shows a strong adherence to secure coding practices, with all identified AJAX handlers and REST API routes properly authenticated and authorized. A high percentage of SQL queries utilize prepared statements, and output escaping is also robust, with over 90% of outputs properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further reduces the attack surface. The taint analysis also revealed no critical or high severity issues with unsanitized paths.
However, the plugin's vulnerability history presents a significant concern. It has a history of two known CVEs, including one critical vulnerability, despite the latest vulnerability being recorded only recently in May 2024 and being marked as currently unpatched. The common vulnerability types noted (SQL Injection and Missing Authorization) are serious and directly address fundamental security controls that should be present. While the current code analysis suggests these specific issues might have been addressed or were not present in this version, the historical pattern of critical vulnerabilities, particularly SQL Injection, warrants caution. The presence of only 3 nonces and 1 capability check across 5 entry points, while not indicative of immediate compromise in this specific version's analysis, could be a contributing factor to past vulnerabilities if not implemented strategically. Therefore, while the current code appears to have addressed many security best practices, the past critical vulnerabilities suggest a potential for recurring issues or a need for more stringent and comprehensive security audits.
In conclusion, the "country-state-city-auto-dropdown" plugin version 2.7.6 demonstrates a solid foundation of secure coding in its current state, with strong authentication, authorization, SQL sanitization, and output escaping. The absence of immediate critical flaws in the static and taint analysis is a positive sign. Nevertheless, the plugin's past critical vulnerabilities, particularly in SQL injection and authorization, remain a notable weakness. Users should exercise caution and ensure the plugin is always updated to the latest version as soon as security patches are released, given the history of critical flaws.
Key Concerns
- Unpatched critical CVE in vulnerability history
- Past critical CVEs indicate potential for recurring issues
- History of SQL Injection vulnerabilities
- History of Missing Authorization vulnerabilities
Country State City Dropdown CF7 Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Country State City Dropdown CF7 <= 2.7.2 - Unauthenticated SQL Injection
Country State City Dropdown CF7 <= 2.7.1 - Missing Authorization
Country State City Dropdown CF7 Release Timeline
Country State City Dropdown CF7 Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Country State City Dropdown CF7 Attack Surface
AJAX Handlers 5
WordPress Hooks 20
Maintenance & Trust
Country State City Dropdown CF7 Maintenance & Trust
Maintenance Signals
Community Trust
Country State City Dropdown CF7 Alternatives
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR)
contact-form-7-image-captcha
Adds an Image CAPTCHA to Contact Form 7 and WPForms, GDPR ready, perfect WPForms or Contact Form 7 Spam Protection Image CAPTCHA, adds a honeypot
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
Ultra Addons for Contact Form 7
ultimate-addons-for-contact-form-7
50+ Essential Addons for Contact Form 7 - Conditional Fields, Multi Step, Redirection, Columns, WooCommerce, Mailchimp & more
GSheetConnector for CF7 – Connect Contact Form 7 to Google Sheets and Send Form Submissions in Real Time
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
Country State City Dropdown CF7 Developer Profile
5 plugins · 11K total installs
How We Detect Country State City Dropdown CF7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/country-state-city-auto-dropdown/assets/js/script-meta.min.js/wp-content/plugins/country-state-city-auto-dropdown/assets/js/script-meta.min.jscountry-state-city-auto-dropdown/style.css?ver=country-state-city-auto-dropdown/assets/js/script-meta.min.js?ver=HTML / DOM Fingerprints
tc_auto_plugin_meta_proid="tc_auto_plugin_meta_pro"tc_csca_auto_ajax_meta<h3 style='background-color:#f7f7f7'>Country State City Dropdown CF7</h3>