
Live Drag and Drop Builder for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/drag-and-drop-form-builder-for-contact-form-7Use a nice Drag and Drop Form Builder when you Create forms with Contact Form 7.
Is Live Drag and Drop Builder for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 92/100Live Drag and Drop Builder for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "drag-and-drop-form-builder-for-contact-form-7" v1.2.8 reveals a generally strong security posture. The absence of dangerous functions, external HTTP requests, file operations, and raw SQL queries is highly commendable. The plugin also demonstrates good practice with a high percentage of properly escaped output and the use of prepared statements for any potential (though none found) SQL interactions. The taint analysis showing zero unsanitized paths is another positive indicator.
However, the complete lack of AJAX handlers, REST API routes, shortcodes, and cron events, while contributing to a minimal attack surface, also means that critical security checks like nonce and capability checks are not implemented on any entry points. This is a concern because if new entry points were introduced or if the plugin's functionality evolved to require them, these essential security layers would be missing by default. The bundled Freemius library, if outdated, could also represent a latent risk.
Given the clean vulnerability history with no recorded CVEs, the plugin appears to have been developed with security in mind. The strengths lie in the absence of common vulnerabilities like SQL injection, XSS through unescaped output, and insecure file operations. The primary area for improvement lies in ensuring that any future or existing entry points are properly secured with nonce and capability checks to mitigate potential vulnerabilities should the attack surface expand.
Key Concerns
- No nonce checks implemented on entry points
- No capability checks implemented on entry points
- Bundled Freemius library (version 1.0)
Live Drag and Drop Builder for Contact Form 7 Security Vulnerabilities
Live Drag and Drop Builder for Contact Form 7 Code Analysis
Bundled Libraries
Output Escaping
Live Drag and Drop Builder for Contact Form 7 Attack Surface
WordPress Hooks 15
Maintenance & Trust
Live Drag and Drop Builder for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Live Drag and Drop Builder for Contact Form 7 Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Advanced Contact form 7 DB
advanced-cf7-db
Save all contact form 7 form submitted data to the database, View, Ordering, Change field labels and Import/Export data using CSV.
Bootstrap for Contact Form 7
bootstrap-for-contact-form-7
This plugin modifies the output of the popular Contact Form 7 plugin to be styled in compliance with themes using the Bootstrap CSS framework.
Contact Form 7: Accessible Defaults
contact-form-7-accessible-defaults
Replaces the default Contact Form 7 form with an accessible equivalent and provides a suite of selectable base forms.
Date Picker For Contact Form 7
date-picker-for-contact-form-7
Easily add a customizable Date Picker to Contact Form 7. Restrict dates, disable specific days, and improve your booking forms.
Live Drag and Drop Builder for Contact Form 7 Developer Profile
20 plugins · 30K total installs
How We Detect Live Drag and Drop Builder for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/drag-and-drop-form-builder-for-contact-form-7/assets/vendor/form-builder/form-builder.min.js/wp-content/plugins/drag-and-drop-form-builder-for-contact-form-7/assets/vendor/form-builder/form-render.min.js/wp-content/plugins/drag-and-drop-form-builder-for-contact-form-7/assets/vendor/form-builder/control_plugins/textarea.trumbowyg.min.js/wp-content/plugins/drag-and-drop-form-builder-for-contact-form-7/form-styles/style-formBuilder/style-buttonized.css/wp-content/plugins/drag-and-drop-form-builder-for-contact-form-7/assets/js/init.js/wp-content/plugins/drag-and-drop-form-builder-for-contact-form-7/assets/css/cf7_style.css/wp-content/plugins/drag-and-drop-form-builder-for-contact-form-7/assets/css/all.min.css/wp-content/plugins/drag-and-drop-form-builder-for-contact-form-7/assets/vendor/form-builder/languages//wp-content/plugins/drag-and-drop-form-builder-for-contact-form-7/assets/vendor/form-builder/form-builder.min.js/wp-content/plugins/drag-and-drop-form-builder-for-contact-form-7/assets/vendor/form-builder/form-render.min.js/wp-content/plugins/drag-and-drop-form-builder-for-contact-form-7/assets/vendor/form-builder/control_plugins/textarea.trumbowyg.min.js/wp-content/plugins/drag-and-drop-form-builder-for-contact-form-7/assets/js/init.jsdrag-and-drop-form-builder-for-contact-form-7/assets/vendor/form-builder/form-builder.min.js?ver=drag-and-drop-form-builder-for-contact-form-7/assets/vendor/form-builder/form-render.min.js?ver=drag-and-drop-form-builder-for-contact-form-7/assets/vendor/form-builder/control_plugins/textarea.trumbowyg.min.js?ver=drag-and-drop-form-builder-for-contact-form-7/form-styles/style-formBuilder/style-buttonized.css?ver=drag-and-drop-form-builder-for-contact-form-7/assets/js/init.js?ver=drag-and-drop-form-builder-for-contact-form-7/assets/css/cf7_style.css?ver=drag-and-drop-form-builder-for-contact-form-7/assets/css/all.min.css?ver=HTML / DOM Fingerprints
vg_cf7_form_builder<!-- Note. You shouldn´t use this tab when using the form builder because it will get overwritten. This tab is available for old forms that were created without the form builder. -->vg_form_builder_fieldsvg_two_columnsvgcf7b_form_builder_settingswpCf7ScriptUrl