Email Reports for CFDB7 Security & Risk Analysis

wordpress.org/plugins/email-reports-for-cfdb7

Send scheduled email reports of Contact Form 7 submissions.

10 active installs v0.0.5 PHP 7.0+ WP 3.3+ Updated Sep 18, 2025
cfdb7contactemailformreport
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Email Reports for CFDB7 Safe to Use in 2026?

Generally Safe

Score 100/100

Email Reports for CFDB7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "email-reports-for-cfdb7" plugin version 0.0.5 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs and a lack of critical or high-severity issues in the vulnerability history are positive indicators. Furthermore, the code analysis shows a robust approach with 100% of SQL queries using prepared statements, a high rate of output escaping (91%), and the presence of nonce and capability checks, suggesting good development practices to prevent common web vulnerabilities.

However, a potential area of concern lies in the limited scope of the static analysis itself. While the provided data indicates zero entry points (AJAX handlers, REST API routes, shortcodes, cron events) that are unprotected, this could simply mean that the plugin has a very minimal attack surface or that the analysis did not uncover all potential interaction points. The presence of a file operation, although not explicitly flagged as risky, warrants careful review in a deeper analysis, as does the fact that only 2 flows were analyzed for taint, which is a very small sample size. Despite these minor points of caution, the plugin appears to be developed with security in mind, with no immediate critical vulnerabilities identified.

In conclusion, the "email-reports-for-cfdb7" plugin v0.0.5 appears to be relatively secure. The development team has implemented good practices like prepared statements and output escaping. The lack of historical vulnerabilities further bolsters confidence. The primary weakness is not a flaw in the code itself, but rather the limited visibility provided by the static analysis, suggesting that a more comprehensive audit might be beneficial to confirm the absence of any subtle vulnerabilities or to identify any potential edge cases that were not covered.

Key Concerns

  • Limited taint flow analysis
  • File operations present, but not detailed
Vulnerabilities
None known

Email Reports for CFDB7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Email Reports for CFDB7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
3
32 escaped
Nonce Checks
2
Capability Checks
2
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

91% escaped35 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
AJAX_SaveSettings (email-reports-for-cfdb7.php:400)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Email Reports for CFDB7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuemail-reports-for-cfdb7.php:38
actionadmin_post_ERF_CFDB7_SAVE_SETTINGSemail-reports-for-cfdb7.php:41
actionadmin_post_ERF_CFDB7_SEND_EMAILemail-reports-for-cfdb7.php:44
actionphpmailer_initemail-reports-for-cfdb7.php:587
Maintenance & Trust

Email Reports for CFDB7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 18, 2025
PHP min version7.0
Downloads248

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Email Reports for CFDB7 Developer Profile

Inbound Horizons

5 plugins · 270 total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Email Reports for CFDB7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/email-reports-for-cfdb7/assets/Email-Reports-for-CFDB7.jpg
Version Parameters
email-reports-for-cfdb7/email-reports-for-cfdb7.php?ver=

HTML / DOM Fingerprints

CSS Classes
plugin-imagepanel-margin
Data Attributes
name="frequency"name="time_period"name="recipients"name="send_time"name="clear_data"name="erf_cfdb7_nonce"+2 more
FAQ

Frequently Asked Questions about Email Reports for CFDB7