Email Customizer for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/email-customizer-for-contact-form-7

Allows customizing the email design from Contact Form 7 with layouts, colors, images, and logos to match your brand's style.

100 active installs v1.0.5 PHP 5.2+ WP 2.0+ Updated Nov 28, 2025
contact-form-7-mailcontact-form-emailemailemail-builderemail-contact-form-7
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Email Customizer for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Email Customizer for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "email-customizer-for-contact-form-7" plugin, in version 1.0.5, exhibits a generally strong security posture. The static analysis reveals an extremely limited attack surface with no unprotected entry points, and all identified SQL queries utilize prepared statements. The plugin demonstrates good output escaping practices, with 98% of outputs being properly escaped, and includes nonce and capability checks for its limited entry points.

Concerns are minimal, revolving around the presence of two external HTTP requests and a single file operation, which, while not inherently vulnerabilities, represent potential vectors for further exploitation if not handled securely. The absence of any recorded vulnerabilities in its history is a positive indicator of good development practices and diligent security awareness.

Overall, this plugin appears to be well-developed from a security perspective. The strengths lie in its minimal attack surface, robust input validation (implied by lack of taint issues), and secure coding practices for data handling. The few identified areas for potential scrutiny are external interactions and file operations, which warrant attention but do not present immediate, high-severity risks based on the provided data.

Key Concerns

  • External HTTP requests detected
  • File operations detected
Vulnerabilities
None known

Email Customizer for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Email Customizer for Contact Form 7 Release Timeline

v1.0.5Current
Code Analysis
Analyzed Mar 16, 2026

Email Customizer for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
54 escaped
Nonce Checks
1
Capability Checks
2
File Operations
1
External Requests
2
Bundled Libraries
0

Output Escaping

98% escaped55 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<processing> (backend\processing.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Email Customizer for Contact Form 7 Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_yeekit_dismiss_notyyeekit\document.php:13
WordPress Hooks 16
actionyeemail_header_builderbackend\processing.php:5
actionsave_post_yeemail_templatebackend\processing.php:6
actionsave_post_wpcf7_contact_formbackend\processing.php:7
filteryeemail_contact_form_7_settingsbackend\processing.php:8
filterwpcf7_mail_componentsbackend\processing.php:9
filteryeemail_shortcodesbackend\processing.php:10
actionplugins_loadedemail-customizer-for-contact-form-7.php:18
actionadmin_noticesemail-customizer-for-contact-form-7.php:40
actionadmin_menuyeekit\document.php:10
actionadmin_enqueue_scriptsyeekit\document.php:11
filterfluentform_global_addonsyeekit\document.php:12
actionadmin_noticesyeekit\document.php:14
actionelementor/element/form/section_form_options/after_section_endyeekit\document.php:15
actionadmin_inityeekit\document.php:17
actionelementor/editor/after_enqueue_stylesyeekit\document.php:19
filterhttp_responseyeekit\document.php:208
Maintenance & Trust

Email Customizer for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version5.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Email Customizer for Contact Form 7 Developer Profile

add-ons.org

59 plugins · 26K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
48 days
View full developer profile
Detection Fingerprints

How We Detect Email Customizer for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/email-customizer-for-contact-form-7/yeekit/css/yeekit-style.css
Script Paths
/wp-content/plugins/email-customizer-for-contact-form-7/yeekit/js/yeekit-script.js
Version Parameters
email-customizer-for-contact-form-7/yeekit/css/yeekit-style.css?ver=email-customizer-for-contact-form-7/yeekit/js/yeekit-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
yeekit_addons_listyee-installyee-pro
Data Attributes
data-yeekit-dismiss
JS Globals
yeekit_document_addons
FAQ

Frequently Asked Questions about Email Customizer for Contact Form 7