
Database for CF7 Security & Risk Analysis
wordpress.org/plugins/database-for-cf7Save CF7 submitted form informations into your WordPress database.
Is Database for CF7 Safe to Use in 2026?
Generally Safe
Score 92/100Database for CF7 has a strong security track record. Known vulnerabilities have been patched promptly.
The "database-for-cf7" plugin v1.2.6 exhibits a mixed security posture. While it demonstrates good practices in areas like prepared statement usage for SQL queries and a high percentage of properly escaped output, significant concerns remain. The presence of a dangerous function like `unserialize` combined with an unprotected AJAX handler presents a notable risk. Although taint analysis shows no critical or high severity unsanitized paths, the potential for `unserialize` to be exploited if data is not properly validated before being processed is a serious threat, especially when coupled with an accessible entry point.
The vulnerability history shows one medium severity CVE related to Missing Authorization, which aligns with the identified unprotected AJAX handler. The fact that this vulnerability is no longer unpatched is positive, but the pattern of authorization issues suggests ongoing diligence is required. The plugin's strengths lie in its robust SQL querying and output escaping, but the single unprotected AJAX endpoint and the `unserialize` function create a clear attack vector that could be exploited to execute arbitrary code or lead to data leakage if not mitigated.
In conclusion, while "database-for-cf7" has made efforts in secure coding for database interactions and output handling, the critical vulnerability of an unprotected AJAX handler coupled with the dangerous `unserialize` function poses a significant risk. The historical medium vulnerability also points to a recurring theme of authorization weaknesses. Administrators should be aware of these potential entry points for exploitation.
Key Concerns
- AJAX handler without authentication check
- Use of dangerous function (unserialize)
- Missing authorization vulnerability history
Database for CF7 Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Database for CF7 <= 1.2.4 - Missing Authorization via wpcf7db_delete AJAX action
Database for CF7 Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Database for CF7 Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
Database for CF7 Maintenance & Trust
Maintenance Signals
Community Trust
Database for CF7 Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
WPSyncSheets For Contact Form 7 – CF7 Google Sheets Connector & Save to Database
contactsheets-lite
Connect Contact Form 7 submissions to Google Sheets to sync your form entries and save all cf7 forms submitted data to the database.
PeproDev CF7 Database
pepro-cf7-database
Reliable Solution to Save CF7 Submissions and Files, Works with CF7 v.5.9+
PeproDev CF7 SMS Notifier
pepro-cf7-sms-notifier
Send notifications to User and Admins upon Contact Form 7 Submission
Newsletter for Contact Form 7
newsletter-for-contact-form-7
List building, create, send and track e-mails for Contact Form 7
Database for CF7 Developer Profile
3 plugins · 8K total installs
How We Detect Database for CF7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/database-for-cf7/resources/css/wpcf7db.css/wp-content/plugins/database-for-cf7/resources/css/wpcf7db.min.css/wp-content/plugins/database-for-cf7/resources/js/wpcf7db.js/wp-content/plugins/database-for-cf7/resources/js/wpcf7db.min.js/wp-content/plugins/database-for-cf7/libs/datatables/css/jquery.dataTables.min.css/wp-content/plugins/database-for-cf7/libs/datatables/css/buttons.dataTables.min.css/wp-content/plugins/database-for-cf7/libs/datatables/js/jquery.dataTables.min.js/wp-content/plugins/database-for-cf7/libs/datatables/js/dataTables.buttons.min.js+7 more/wp-content/plugins/database-for-cf7/resources/js/wpcf7db.js/wp-content/plugins/database-for-cf7/resources/js/wpcf7db.min.jsdatabase-for-cf7/resources/css/wpcf7db.css?ver=database-for-cf7/resources/js/wpcf7db.js?ver=HTML / DOM Fingerprints
wpcf7db-tabledata-nonceparameters