Contact Form 7 Email Validation Security & Risk Analysis

wordpress.org/plugins/email-domain-verification-in-cf7

Contact Form 7 Email Validation plugin adds an extended validation to verify domain in email address for email fields of Contact Form 7 plugin.

1K active installs v3.5.2 PHP + WP 4.9+ Updated Dec 18, 2020
contact-form-7domain-verificationemailvalidation
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Contact Form 7 Email Validation Safe to Use in 2026?

Generally Safe

Score 85/100

Contact Form 7 Email Validation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin 'email-domain-verification-in-cf7' version 3.5.2 demonstrates a strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are 100% prepared, and all output is properly escaped, indicating good coding practices for preventing common web vulnerabilities. The absence of file operations and external HTTP requests further reduces the attack surface. The plugin also shows no history of known vulnerabilities (CVEs), which is a very positive sign of its stability and security over time.

While the static analysis reveals a clean codebase with no critical or high-severity issues detected in taint flows or direct code signals, the complete absence of identified entry points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual. This could mean the plugin has a very limited or no functional impact, or that the static analysis tool was unable to identify these components. The presence of only one capability check is also notable, suggesting the plugin's functionality might not require extensive user privilege verification, which could be a concern if sensitive actions were performed without proper authorization. However, without any specific vulnerabilities identified in the code signals or history, the overall risk is assessed as very low.

In conclusion, the plugin exhibits excellent security development practices with no known vulnerabilities or concerning code patterns detected in this analysis. The primary area for potential improvement or further investigation would be to confirm the completeness of the identified attack surface, as its current reported zero entry points is atypical for a functional WordPress plugin. Despite this anomaly, the lack of any detected security flaws makes it a relatively safe plugin to use.

Key Concerns

  • Missing nonce checks on AJAX handlers
  • Missing permission callbacks on REST API routes
  • Dangerous functions found in code
  • SQL queries without prepared statements
  • Unescaped output found
  • File operations detected
  • External HTTP requests detected
  • Bundled outdated libraries
  • Unpatched CVEs found
  • Critical severity taint flow
  • High severity taint flow
  • Unusual lack of identified entry points
  • Limited capability checks detected
Vulnerabilities
None known

Contact Form 7 Email Validation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Contact Form 7 Email Validation Release Timeline

v3.5.2Current
v3.0.1
v3.0
v2.0
v1.0
Code Analysis
Analyzed Mar 16, 2026

Contact Form 7 Email Validation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Contact Form 7 Email Validation Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initcontact-form-7-email-validation-check.php:26
actionadmin_noticescontact-form-7-email-validation-check.php:32
filterwpcf7_validate_emailcontact-form-7-email-validation-check.php:91
filterwpcf7_validate_email*contact-form-7-email-validation-check.php:92
actionplugins_loadedcontact-form-7-email-validation-check.php:97
Maintenance & Trust

Contact Form 7 Email Validation Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedDec 18, 2020
PHP min version
Downloads27K

Community Trust

Rating66/100
Number of ratings10
Active installs1K
Developer Profile

Contact Form 7 Email Validation Developer Profile

Clarion Technologies

3 plugins · 2K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Contact Form 7 Email Validation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Contact Form 7 Email Validation