
DM Contact Form 7 DB Security & Risk Analysis
wordpress.org/plugins/dm-contact-form-7-dbSave Contact Form 7 entries.
Is DM Contact Form 7 DB Safe to Use in 2026?
Generally Safe
Score 100/100DM Contact Form 7 DB has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "dm-contact-form-7-db" plugin version 1.0.2 exhibits a mixed security posture. On the positive side, there are no recorded vulnerabilities (CVEs) and the plugin doesn't appear to have a large attack surface through common entry points like AJAX handlers, REST API routes, or shortcodes. Furthermore, a high percentage of output is properly escaped, indicating an effort to prevent basic cross-site scripting (XSS) issues.
However, significant concerns arise from the static code analysis. The presence of the `unserialize` function is a major red flag, as it can be exploited for object injection vulnerabilities if not handled with extreme care and validation. The fact that all 17 SQL queries are not using prepared statements is another critical weakness, making the plugin highly susceptible to SQL injection attacks. The taint analysis also revealed one flow with an unsanitized path, which could potentially lead to further security issues. The lack of capability checks for any entry points is concerning, as it suggests that even if entry points existed, they might not be adequately protected against unauthorized access.
Given the absence of known historical vulnerabilities, it's difficult to draw firm conclusions about past security practices. However, the current code analysis reveals fundamental security oversights that could lead to severe vulnerabilities. The plugin's strengths lie in its limited attack surface and good output escaping, but these are heavily overshadowed by the risks associated with `unserialize`, raw SQL queries, and the lack of capability checks.
Key Concerns
- Unsanitized SQL queries
- Dangerous function: unserialize
- Flows with unsanitized paths
- No capability checks
DM Contact Form 7 DB Security Vulnerabilities
DM Contact Form 7 DB Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
DM Contact Form 7 DB Attack Surface
WordPress Hooks 7
Maintenance & Trust
DM Contact Form 7 DB Maintenance & Trust
Maintenance Signals
Community Trust
DM Contact Form 7 DB Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Advanced Contact form 7 DB
advanced-cf7-db
Save all contact form 7 form submitted data to the database, View, Ordering, Change field labels and Import/Export data using CSV.
WP Contact Form 7 DB Handler
wp-contact-form-7-db-handler
Store all your contact form 7 submission and easily access it. you can also filter and export it!
Contact Form Dashboard
contact-form-dashboard
CFD stores, organizes and presents all the submissions of the Contact Form 7 in a simplest way. It supports other interesting features like - Dashboard Analytics, Bulk emails / replies handling; Search, sort and export messages.
Live Drag and Drop Builder for Contact Form 7
drag-and-drop-form-builder-for-contact-form-7
Use a nice Drag and Drop Form Builder when you Create forms with Contact Form 7.
DM Contact Form 7 DB Developer Profile
1 plugin · 300 total installs
How We Detect DM Contact Form 7 DB
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dm-contact-form-7-db/assets/css/style.css/wp-content/plugins/dm-contact-form-7-db/assets/js/scripts.js/wp-content/plugins/dm-contact-form-7-db/assets/js/scripts.jswp_cf7db/assets/css/style.css?ver=wp_cf7db/assets/js/scripts.js?ver=HTML / DOM Fingerprints
WP_CF7DB_Ajax_Obj