Database Entries Form 7 Security & Risk Analysis

wordpress.org/plugins/database-entries-form-7

Effortlessly manage and store all form submissions from Contact Form 7 in one centralized location.

10 active installs v1.1.0 PHP 7.4+ WP 5.0+ Updated Dec 19, 2025
contact-form-7database-entries-form
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Database Entries Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Database Entries Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "database-entries-form-7" plugin version 1.1.0 exhibits a generally good security posture, with a significant majority of SQL queries using prepared statements and a high percentage of output being properly escaped. The presence of numerous nonce and capability checks on its limited entry points further strengthens its defenses. However, the static analysis reveals potential areas of concern, particularly the use of the `unserialize()` function three times. While the taint analysis shows no critical or high severity flows with unsanitized paths, it does indicate four high severity flows with unsanitized paths, which warrants investigation as it could represent potential vulnerabilities if input is not handled rigorously. The plugin's clean vulnerability history is a positive indicator of past security diligence, suggesting that developers have been responsive to security concerns. Overall, while the plugin has strong foundational security practices and a clean history, the identified dangerous functions and high severity taint flows introduce some risk that should be addressed.

Key Concerns

  • Use of unserialize() function
  • High severity taint flows
Vulnerabilities
None known

Database Entries Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Database Entries Form 7 Code Analysis

Dangerous Functions
3
Raw SQL Queries
1
32 prepared
Unescaped Output
20
193 escaped
Nonce Checks
8
Capability Checks
1
File Operations
3
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$valuedetailsdecoded = unserialize($valuedetail['value']);modules\entries-form-module\templates\entries\entries-detail-page.php:84
unserialize$selected_values = is_serialized($valuedetail['value']) ? unserialize($valuedetail['value']) : (arramodules\entries-form-module\templates\entries\entries-detail-page.php:94
unserialize$valuedetailsdecoded = unserialize($data['value']);modules\entries-form-module\templates\entries\list-entries-page.php:312

SQL Query Safety

97% prepared33 total queries

Output Escaping

91% escaped213 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

6 flows4 with unsanitized paths
def7_get_entries_detail (modules\entries-form-module\entries-form-class.php:712)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Database Entries Form 7 Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_export_csvmodules\entries-form-module\entries-form-class.php:44
noprivwp_ajax_export_csvmodules\entries-form-module\entries-form-class.php:45
WordPress Hooks 3
actionadmin_enqueue_scriptsmodules\entries-form-module\entries-form-class.php:35
actionadmin_menumodules\entries-form-module\entries-form-class.php:38
actionwpcf7_before_send_mailmodules\entries-form-module\entries-form-class.php:41
Maintenance & Trust

Database Entries Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 19, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Database Entries Form 7 Developer Profile

Centous Solutions

3 plugins · 80 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Database Entries Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/database-entries-form-7/assets/css/style.css/wp-content/plugins/database-entries-form-7/assets/js/main.js
Script Paths
/wp-content/plugins/database-entries-form-7/assets/js/main.js
Version Parameters
database-entries-form-7/assets/css/style.css?ver=database-entries-form-7/assets/js/main.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Database Entries Form 7