Custom Post Type List Field For Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/custom-post-type-list-field-for-contact-form-7

Custom Post Type List Field For Contact Form 7 Custom Post Type List Field For Contact Form 7 Custom Post Type List Field For Contact Form 7 using to …

300 active installs v1.0 PHP 5.0+ WP + Updated Jan 31, 2026
custom-dropdowncustom-post-drop-downcustom-post-listmultiple-select-contact-form-7post-types-contact-form-7
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Custom Post Type List Field For Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Custom Post Type List Field For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin "custom-post-type-list-field-for-contact-form-7" v1.0 exhibits a generally positive security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events suggests a very limited attack surface, which is a significant strength. Furthermore, the fact that all observed SQL queries utilize prepared statements and there are no file operations or external HTTP requests indicate good development practices in these critical areas. The absence of known vulnerabilities and CVEs in its history further contributes to a perception of a secure plugin.

However, the analysis does highlight a few areas for concern. While the majority of output is properly escaped, 28% of outputs remain unescaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if malicious data is ever processed and displayed. The total lack of nonce and capability checks across the entire plugin, though seemingly moot given the absence of entry points, represents a potential weakness if future versions introduce any. The use of bundled libraries like Select2, without version information, carries a potential risk if that library has known vulnerabilities and is not kept up-to-date.

In conclusion, the plugin is currently in a strong security state due to its minimal attack surface and good SQL handling. The primary points of attention are the unescaped outputs and the complete absence of authentication and authorization checks, which, while not immediately exploitable, represent foundational security gaps. The bundled library also warrants scrutiny for potential outdatedness. Addressing these specific points would further solidify its security.

Key Concerns

  • Unescaped output detected
  • Missing nonce checks
  • Missing capability checks
  • Bundled library without version info (Select2)
Vulnerabilities
None known

Custom Post Type List Field For Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Custom Post Type List Field For Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

72% escaped25 total outputs
Attack Surface

Custom Post Type List Field For Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
filterplugin_row_metacustom-post-type-list-field-cf7.php:46
actionadmin_initmain\backend\cptlfcf7-post-control.php:194
filterwpcf7_validate_postsmain\frontend\cptlfcf7-post.php:8
filterwpcf7_validate_posts*main\frontend\cptlfcf7-post.php:9
actionwpcf7_initmain\frontend\cptlfcf7-post.php:31
actionadmin_initmain\resources\cptlfcf7-installation-require.php:4
actionadmin_noticesmain\resources\cptlfcf7-installation-require.php:12
actionplugins_loadedmain\resources\cptlfcf7-language.php:4
filterload_textdomain_mofilemain\resources\cptlfcf7-language.php:18
actionadmin_enqueue_scriptsmain\resources\cptlfcf7-load-js-css.php:4
actionwp_enqueue_scriptsmain\resources\cptlfcf7-load-js-css.php:14
Maintenance & Trust

Custom Post Type List Field For Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 31, 2026
PHP min version5.0
Downloads3K

Community Trust

Rating100/100
Number of ratings3
Active installs300
Developer Profile

Custom Post Type List Field For Contact Form 7 Developer Profile

silverplugins217

21 plugins · 12K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect Custom Post Type List Field For Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/js/back.js/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/css/admin.css/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/js/front.js/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/js/select2.js/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/css/select2.css/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/css/front.css
Script Paths
/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/js/back.js/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/js/front.js/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/js/select2.js
Version Parameters
cptlfcf7-back-js?ver=1.0.0cptlfcf7-admin-css?ver=1.0.0cptlfcf7-front-js?ver=1.0.0cptlfcf7-select2-js?ver=1.0.0cptlfcf7-select2-css?ver=1.0.0cptlfcf7-front-css?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
wpcf7-form-controlwpcf7-select
Data Attributes
aria-requiredaria-invalid
Shortcode Output
<select name=" name=" id="tabindex="
FAQ

Frequently Asked Questions about Custom Post Type List Field For Contact Form 7