Style Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/customizer-block-cf7

This Contact Form 7 compatible Gutenberg Block automates CSS style generation allowing you to quickly design visually appealing contact forms.

1K active installs v1.3 PHP 7.4+ WP 6.0+ Updated Apr 11, 2025
cf7contact-form-7contact-form-7-stylecontact-forms
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Style Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Style Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The customizer-block-cf7 plugin version 1.3 appears to have a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events, particularly unprotected ones, significantly limits the potential attack surface. Furthermore, the code's reliance on prepared statements for SQL queries, high percentage of properly escaped output, and the presence of capability checks are positive indicators of secure coding practices. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting a history of secure development or effective patching. The taint analysis also yielded no critical or high severity flows, further reinforcing the impression of a robustly secured plugin.

While the static analysis shows a positive security outlook, the complete lack of any identified entry points (AJAX, REST, shortcodes, cron) is unusual and could either indicate a very niche or simple plugin, or potentially that the analysis tool might have limitations in detecting certain types of interactions. The zero nonce checks is also a point of note, although without identified entry points that typically require them, it's not immediately a critical issue. The plugin's strengths lie in its evident effort to avoid common pitfalls like raw SQL and unescaped output. The lack of any vulnerability history is a significant positive, pointing towards a stable and secure plugin. The overall risk assessment is low, with the primary potential concern being the lack of detected entry points which might warrant a deeper manual code review if further context was available.

Vulnerabilities
None known

Style Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Style Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
11 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

92% escaped12 total outputs
Attack Surface

Style Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
filteradmin_footer_textadmin\cfcf7-admin.php:94
actionadmin_initcustomizer-block-cf7.php:45
actioninitcustomizer-block-cf7.php:125
actioninitgutenberg-block\block-patterns.php:27
actioninitgutenberg-block\block-patterns.php:215
actionadmin_enqueue_scriptsincludes\cfcf7-functions.php:29
actionadmin_menuincludes\cfcf7-functions.php:54
actionadmin_initincludes\cfcf7-functions.php:71
actionnetwork_admin_noticesincludes\cfcf7-functions.php:78
actionadmin_noticesincludes\cfcf7-functions.php:80
actionadmin_enqueue_scriptsincludes\cfcf7-functions.php:111
Maintenance & Trust

Style Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 11, 2025
PHP min version7.4
Downloads11K

Community Trust

Rating94/100
Number of ratings7
Active installs1K
Developer Profile

Style Contact Form 7 Developer Profile

mofis

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Style Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/customizer-block-cf7/admin/css/cfcf7-admin.css
Version Parameters
customizer-block-cf7/style.css?ver=customizer-block-cf7/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
cfcf7-blockcfcf7-block-containerno-form-message
Data Attributes
data-block="customizer-block-cf7/customizer-block-cf7"
JS Globals
window.cfcf7
Shortcode Output
[contact-form-7
FAQ

Frequently Asked Questions about Style Contact Form 7