Easy Build CF7 Light Security & Risk Analysis

wordpress.org/plugins/easy-build-cf7-light

A visual form builder that lets you create beautiful Contact Form 7 forms using Elementor's drag & drop interface.

10 active installs v1.0.4 PHP 7.4+ WP 5.0+ Updated Feb 26, 2026
cf7contact-form-7elementorform-buildervisual-builder
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easy Build CF7 Light Safe to Use in 2026?

Generally Safe

Score 100/100

Easy Build CF7 Light has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "easy-build-cf7-light" v1.0.4 exhibits a generally good security posture with several strong practices. The complete absence of SQL injection vulnerabilities through the consistent use of prepared statements, the high percentage of properly escaped output, and the presence of nonce and capability checks for most entry points are all positive indicators. Furthermore, the lack of any recorded vulnerabilities in its history suggests a history of secure development or effective patching by its maintainers.

However, a significant concern arises from the presence of an unprotected AJAX handler. With a total of 4 AJAX handlers identified, one lacking any authentication checks presents a direct attack vector. While the static analysis did not reveal any dangerous functions, critical taint flows, or raw SQL queries, this single unprotected entry point can be exploited to perform unintended actions if it handles user-supplied data without proper validation or authorization. The limited number of entry points also means that this one unprotected handler represents a substantial portion of the plugin's attack surface that is vulnerable to unauthenticated access.

In conclusion, the plugin has a solid foundation in terms of secure coding practices, particularly regarding database interactions and output sanitization. The vulnerability history is reassuring. The primary weakness lies in the single unprotected AJAX endpoint, which requires immediate attention to mitigate the risk of unauthorized access and potential exploitation.

Key Concerns

  • AJAX handler without auth check
Vulnerabilities
None known

Easy Build CF7 Light Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Easy Build CF7 Light Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
313 escaped
Nonce Checks
4
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped328 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<Sync> (includes\Sync.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Easy Build CF7 Light Attack Surface

Entry Points4
Unprotected1

AJAX Handlers 4

authwp_ajax_get_cf7_formsincludes\Ajax.php:21
authwp_ajax_create_cf7_builder_postincludes\Ajax.php:22
authwp_ajax_cf7_builder_syncincludes\Ajax.php:23
authwp_ajax_cf7_builder_syncincludes\Sync.php:14
WordPress Hooks 14
actionplugins_loadedeasy-build-cf7-light.php:47
filtermanage_easy-build-cf7_posts_columnsincludes\Admin\Handler.php:29
actionmanage_easy-build-cf7_posts_custom_columnincludes\Admin\Handler.php:30
actionadmin_noticesincludes\Admin.php:29
actionwp_enqueue_scriptsincludes\Assets.php:25
actionadmin_enqueue_scriptsincludes\Assets.php:26
actionelementor/elements/categories_registeredincludes\Elementor.php:28
actionelementor/widgets/widgets_registeredincludes\Elementor.php:29
actionelementor/editor/after_enqueue_scriptsincludes\Elementor.php:30
actioninitincludes\Generator.php:13
actionadd_meta_boxesincludes\Generator.php:14
actionadd_meta_boxesincludes\Generator.php:15
actionsave_postincludes\Generator.php:16
actionwpcf7_admin_footerincludes\Sync.php:15
Maintenance & Trust

Easy Build CF7 Light Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.4
Downloads449

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Easy Build CF7 Light Developer Profile

Loyalcoders

3 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easy Build CF7 Light

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/easy-build-cf7-light/assets/js/frontend.js/wp-content/plugins/easy-build-cf7-light/assets/dist/main.css/wp-content/plugins/easy-build-cf7-light/assets/dist/admin.css/wp-content/plugins/easy-build-cf7-light/assets/dist/admin.bundle.js/wp-content/plugins/easy-build-cf7-light/assets/dist/adminAjax.bundle.js/wp-content/plugins/easy-build-cf7-light/assets/dist/sync.bundle.js/wp-content/plugins/easy-build-cf7-light/assets/dist/sync.css
Script Paths
/wp-content/plugins/easy-build-cf7-light/assets/js/frontend.js/wp-content/plugins/easy-build-cf7-light/assets/dist/admin.bundle.js/wp-content/plugins/easy-build-cf7-light/assets/dist/adminAjax.bundle.js/wp-content/plugins/easy-build-cf7-light/assets/dist/sync.bundle.js
Version Parameters
easy-build-cf7-light/assets/js/frontend.js?ver=easy-build-cf7-light/assets/dist/main.css?ver=easy-build-cf7-light/assets/dist/admin.css?ver=easy-build-cf7-light/assets/dist/admin.bundle.js?ver=easy-build-cf7-light/assets/dist/adminAjax.bundle.js?ver=easy-build-cf7-light/assets/dist/sync.bundle.js?ver=easy-build-cf7-light/assets/dist/sync.css?ver=

HTML / DOM Fingerprints

CSS Classes
easy-build-cf7-light-admin-styleeasy-build-cf7-light-admin-scripteasy-build-cf7-light-ajaxeasy-build-cf7-light-synceasy-build-cf7-light-sync-style
JS Globals
easyBuilderCf7lightObj
FAQ

Frequently Asked Questions about Easy Build CF7 Light