
Double Opt-in for CF7 Security & Risk Analysis
wordpress.org/plugins/double-opt-in-for-cf7This plugin adds a double opt-in functionality to CF7 forms.
Is Double Opt-in for CF7 Safe to Use in 2026?
Generally Safe
Score 100/100Double Opt-in for CF7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "double-opt-in-for-cf7" v1.0.1 presents a generally good security posture, with no known past vulnerabilities or critical findings in taint analysis. The static analysis shows a very limited attack surface, with all identified entry points either implicitly or explicitly protected by WordPress's security mechanisms. The plugin also demonstrates good practices in terms of capability checks and nonce usage for its identified entry points.
However, the static analysis does reveal two instances of the `unserialize` function, which is a known potential vector for remote code execution if an attacker can control the serialized data passed to it. While there are no external HTTP requests or raw SQL queries without prepared statements, and output escaping is reasonably well-handled, the presence of `unserialize` warrants careful consideration. The lack of recorded vulnerabilities historically is a positive indicator, suggesting the developers may be security-conscious, but it does not negate the inherent risks associated with using potentially dangerous functions.
Key Concerns
- Use of unserialize function
Double Opt-in for CF7 Security Vulnerabilities
Double Opt-in for CF7 Release Timeline
Double Opt-in for CF7 Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Double Opt-in for CF7 Attack Surface
Shortcodes 1
WordPress Hooks 33
Maintenance & Trust
Double Opt-in for CF7 Maintenance & Trust
Maintenance Signals
Community Trust
Double Opt-in for CF7 Alternatives
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
HTML Forms – Simple WordPress Forms Plugin
html-forms
A simpler, faster, and smarter WordPress forms plugin.
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress
wpzoom-forms
Drag & drop contact form builder for WordPress. Create contact forms, custom forms, email forms with spam protection. Works with Elementor, shortcodes
Contact Form Email
contact-form-to-email
Contact form with visual form builder. Contact form that sends the data to email, to a database list and to CSV / Excel files.
Double Opt-in for CF7 Developer Profile
1 plugin · 100 total installs
How We Detect Double Opt-in for CF7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/double-opt-in-for-cf7/inc/js/cf7optin.js/wp-content/plugins/double-opt-in-for-cf7/inc/css/cf7optin.css/wp-content/plugins/double-opt-in-for-cf7/inc/js/cf7optin-fileinput.jsinc/js/cf7optin.jsinc/js/cf7optin-fileinput.jscf7optin-js?ver=cf7optin-style?ver=cf7optin-input-js?ver=HTML / DOM Fingerprints
<!-- Init END -->cf7optinWarningcf7optinInput[cf7doubleoptin]