
Custom Post Type List Field For Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/custom-post-type-list-field-for-contact-form-7Custom Post Type List Field For Contact Form 7 Custom Post Type List Field For Contact Form 7 Custom Post Type List Field For Contact Form 7 using to …
Is Custom Post Type List Field For Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100Custom Post Type List Field For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "custom-post-type-list-field-for-contact-form-7" v1.0 exhibits a generally positive security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events suggests a very limited attack surface, which is a significant strength. Furthermore, the fact that all observed SQL queries utilize prepared statements and there are no file operations or external HTTP requests indicate good development practices in these critical areas. The absence of known vulnerabilities and CVEs in its history further contributes to a perception of a secure plugin.
However, the analysis does highlight a few areas for concern. While the majority of output is properly escaped, 28% of outputs remain unescaped, which could potentially lead to cross-site scripting (XSS) vulnerabilities if malicious data is ever processed and displayed. The total lack of nonce and capability checks across the entire plugin, though seemingly moot given the absence of entry points, represents a potential weakness if future versions introduce any. The use of bundled libraries like Select2, without version information, carries a potential risk if that library has known vulnerabilities and is not kept up-to-date.
In conclusion, the plugin is currently in a strong security state due to its minimal attack surface and good SQL handling. The primary points of attention are the unescaped outputs and the complete absence of authentication and authorization checks, which, while not immediately exploitable, represent foundational security gaps. The bundled library also warrants scrutiny for potential outdatedness. Addressing these specific points would further solidify its security.
Key Concerns
- Unescaped output detected
- Missing nonce checks
- Missing capability checks
- Bundled library without version info (Select2)
Custom Post Type List Field For Contact Form 7 Security Vulnerabilities
Custom Post Type List Field For Contact Form 7 Code Analysis
Bundled Libraries
Output Escaping
Custom Post Type List Field For Contact Form 7 Attack Surface
WordPress Hooks 11
Maintenance & Trust
Custom Post Type List Field For Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Type List Field For Contact Form 7 Alternatives
Smart Post Lists Light
smart-post-lists-light
Create custom post lists based on options you choose from a form in a widget. Different types of lists, blog, portfolio, services pages. No coding.
Advanced Custom Fields: W4 Post List Bridge
advanced-custom-fields-w4-post-list-bridge
This plugin provides a [post_field field="field-name"] shortcode connecting an Advanced Custom Fields field to your W4 Post List list templa …
List Custom Post with featured image
list-custom-post-with-featured-image
Simple plugin. Show feature image, title with pagination on anywhere using shortcode.
UB Ultimate Post List
ub-ultimate-post-list
This plugin registers a block named "Ultimate Post List" which can be used for dynamic listing of selected posts of all custom post types and default post type "Post".
Custom post listing block
custom-post-listing-block
Display custom post listing block with details.
Custom Post Type List Field For Contact Form 7 Developer Profile
21 plugins · 12K total installs
How We Detect Custom Post Type List Field For Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/js/back.js/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/css/admin.css/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/js/front.js/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/js/select2.js/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/css/select2.css/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/css/front.css/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/js/back.js/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/js/front.js/wp-content/plugins/custom-post-type-list-field-for-contact-form-7/assets/js/select2.jscptlfcf7-back-js?ver=1.0.0cptlfcf7-admin-css?ver=1.0.0cptlfcf7-front-js?ver=1.0.0cptlfcf7-select2-js?ver=1.0.0cptlfcf7-select2-css?ver=1.0.0cptlfcf7-front-css?ver=1.0.0HTML / DOM Fingerprints
wpcf7-form-controlwpcf7-selectaria-requiredaria-invalid<select name=" name=" id="tabindex="