
Database Entries Form 7 Security & Risk Analysis
wordpress.org/plugins/database-entries-form-7Effortlessly manage and store all form submissions from Contact Form 7 in one centralized location.
Is Database Entries Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100Database Entries Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "database-entries-form-7" plugin version 1.1.0 exhibits a generally good security posture, with a significant majority of SQL queries using prepared statements and a high percentage of output being properly escaped. The presence of numerous nonce and capability checks on its limited entry points further strengthens its defenses. However, the static analysis reveals potential areas of concern, particularly the use of the `unserialize()` function three times. While the taint analysis shows no critical or high severity flows with unsanitized paths, it does indicate four high severity flows with unsanitized paths, which warrants investigation as it could represent potential vulnerabilities if input is not handled rigorously. The plugin's clean vulnerability history is a positive indicator of past security diligence, suggesting that developers have been responsive to security concerns. Overall, while the plugin has strong foundational security practices and a clean history, the identified dangerous functions and high severity taint flows introduce some risk that should be addressed.
Key Concerns
- Use of unserialize() function
- High severity taint flows
Database Entries Form 7 Security Vulnerabilities
Database Entries Form 7 Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Database Entries Form 7 Attack Surface
AJAX Handlers 2
WordPress Hooks 3
Maintenance & Trust
Database Entries Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Database Entries Form 7 Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 – Dynamic Text Extension
contact-form-7-dynamic-text-extension
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
Database Entries Form 7 Developer Profile
3 plugins · 80 total installs
How We Detect Database Entries Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/database-entries-form-7/assets/css/style.css/wp-content/plugins/database-entries-form-7/assets/js/main.js/wp-content/plugins/database-entries-form-7/assets/js/main.jsdatabase-entries-form-7/assets/css/style.css?ver=database-entries-form-7/assets/js/main.js?ver=