CouponFlow for Gumroad with Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/couponflow-for-gumroad-cf7

Automatically generate and send personalized Gumroad coupon codes from Contact Form 7 submissions.

0 active installs v1.0.0 PHP 8.0+ WP 6.0+ Updated Dec 26, 2025
cf7contact-form-7discount-codesgumroadgumroad-coupons
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CouponFlow for Gumroad with Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

CouponFlow for Gumroad with Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "couponflow-for-gumroad-cf7" plugin version 1.0.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and a very high percentage of properly escaped output are excellent indicators of good development practices. Furthermore, the lack of any recorded historical vulnerabilities (CVEs) is a significant positive. The plugin also demonstrates diligent use of nonces and capability checks on its entry points, which is crucial for preventing unauthorized actions.

However, there are a few areas that warrant attention. The presence of two AJAX handlers, while noted as having authorization checks, represents the plugin's primary attack surface. Any oversight in the implementation of these authorization checks could lead to vulnerabilities. Additionally, the plugin makes two external HTTP requests. Without further inspection, it's impossible to determine if these requests are made securely and if the data sent or received is properly validated, which could potentially introduce risks if the external services are compromised or if the plugin mishandles external data.

In conclusion, the plugin is well-coded with many security best practices implemented. The primary areas for potential concern lie in the two AJAX handlers and the external HTTP requests. Given the clean historical record and the robust code signals, the immediate risk appears low, but continued vigilance and thorough review of the AJAX handler logic and external request handling would be prudent for future versions.

Key Concerns

  • AJAX handlers exist (potential entry points)
  • External HTTP requests present
Vulnerabilities
None known

CouponFlow for Gumroad with Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CouponFlow for Gumroad with Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
39 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

98% escaped40 total outputs
Attack Surface

CouponFlow for Gumroad with Contact Form 7 Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_cf7g_check_connectionsrc\Admin\AjaxController.php:20
authwp_ajax_cf7g_reset_connectionsrc\Admin\AjaxController.php:21
WordPress Hooks 9
actionplugins_loadedcouponflow-for-gumroad-cf7.php:41
actionadmin_noticescouponflow-for-gumroad-cf7.php:48
actionadmin_noticescouponflow-for-gumroad-cf7.php:62
filterwpcf7_editor_panelssrc\Admin\SettingsPage.php:20
actionwpcf7_save_contact_formsrc\Admin\SettingsPage.php:22
actionadmin_enqueue_scriptssrc\Admin\SettingsPage.php:24
actionwpcf7_before_send_mailsrc\Integration\CouponHandler.php:22
filterwpcf7_special_mail_tagssrc\Integration\CouponHandler.php:66
actionwpcf7_initsrc\Integration\MailTag.php:19
Maintenance & Trust

CouponFlow for Gumroad with Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 26, 2025
PHP min version8.0
Downloads113

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CouponFlow for Gumroad with Contact Form 7 Developer Profile

Lucian-DEV

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CouponFlow for Gumroad with Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/couponflow-for-gumroad-cf7/assets/css/admin.css/wp-content/plugins/couponflow-for-gumroad-cf7/assets/js/admin.js
Script Paths
/wp-content/plugins/couponflow-for-gumroad-cf7/assets/js/admin.js
Version Parameters
couponflow-for-gumroad-cf7/assets/css/admin.css?ver=couponflow-for-gumroad-cf7/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
cf7g-gumroad-panelcf7g-mailtag-tip
Data Attributes
data-formdata-nonce
Shortcode Output
[cf7g_coupon_code]
FAQ

Frequently Asked Questions about CouponFlow for Gumroad with Contact Form 7