Emercury Extension For Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/emercury-extension-for-contact-form-7

Immediately add your leads and subscribers directly to Emercury seamlessly with this plugin.

0 active installs v1.0.2 PHP 7.4+ WP 5.8+ Updated Unknown
contact-form-7emailemercuryformsmarketing
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Emercury Extension For Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Emercury Extension For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'emercury-extension-for-contact-form-7' v1.0.2 exhibits a concerning security posture primarily due to its extensive unprotected attack surface. While the code analysis reveals no directly dangerous functions or SQL injection risks, the presence of six AJAX handlers without any authentication or capability checks is a significant vulnerability. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or information disclosure depending on their functionality.

Furthermore, the taint analysis indicates that all five analyzed flows involve unsanitized paths. Although no critical or high-severity issues were flagged in the taint analysis, this finding, combined with the unprotected AJAX handlers, suggests a potential for Cross-Site Scripting (XSS) or other client-side attacks if these paths are directly influenced by user input without proper sanitization and output escaping. The fact that only 68% of outputs are properly escaped further exacerbates this risk. The absence of known CVEs is a positive sign, but it does not negate the immediate risks identified in the static and taint analyses.

In conclusion, while the plugin demonstrates good practices in SQL query handling and file operations, the lack of authorization checks on its AJAX endpoints and the presence of unsanitized paths are critical weaknesses. The plugin's security can be significantly improved by implementing nonce checks and capability checks on all AJAX handlers and ensuring thorough input sanitization and output escaping for all data processed through the identified taint flows. Until these issues are addressed, the plugin should be considered a moderate to high risk.

Key Concerns

  • Unprotected AJAX handlers
  • Unsanitized paths in taint analysis
  • Insufficient output escaping
  • No nonce checks on AJAX
  • No capability checks on AJAX
Vulnerabilities
None known

Emercury Extension For Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Emercury Extension For Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
38 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

68% escaped56 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
eefcf7_emercury_load_alists (includes\find.php:64)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Emercury Extension For Contact Form 7 Attack Surface

Entry Points6
Unprotected6

AJAX Handlers 6

authwp_ajax_eefcf7_emercury_logresetincludes\find.php:2
authwp_ajax_no_priv_eefcf7_emercury_logresetincludes\find.php:3
authwp_ajax_eefcf7_emercury_logloadincludes\find.php:5
authwp_ajax_no_priv_eefcf7_emercury_logloadincludes\find.php:6
authwp_ajax_eefcf7_emercury_load_alistsincludes\find.php:8
authwp_ajax_eefcf7_emercury_load_html_fieldsincludes\find.php:9
WordPress Hooks 11
actionadmin_print_scriptsemercury-extension-cf7.php:73
actionadmin_enqueue_scriptsemercury-extension-cf7.php:79
filterwpcf7_editor_panelsincludes\handler.php:2
actionwpcf7_after_saveincludes\handler.php:3
actionwpcf7_before_send_mailincludes\handler.php:4
filterwpcf7_form_class_attrincludes\handler.php:5
filterwpcf7_form_hidden_fieldsincludes\handler.php:6
filterwpcf7_form_tagincludes\tools.php:12
actioninitincludes\tools.php:20
filterwpcf7_special_mail_tagsincludes\tools.php:54
actionwpcf7_initincludes\tools.php:64
Maintenance & Trust

Emercury Extension For Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Emercury Extension For Contact Form 7 Developer Profile

Emercury

5 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Emercury Extension For Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/emercury-extension-for-contact-form-7/assets/css/emercury-extension-cf7-admin.css/wp-content/plugins/emercury-extension-for-contact-form-7/assets/js/emercury-extension-cf7.js
Script Paths
/wp-content/plugins/emercury-extension-for-contact-form-7/assets/js/emercury-extension-cf7.js
Version Parameters
emercury-extension-for-contact-form-7/assets/css/emercury-extension-cf7-admin.css?ver=emercury-extension-for-contact-form-7/assets/js/emercury-extension-cf7.js?ver=

HTML / DOM Fingerprints

CSS Classes
eefcf7eefcf7-emercury
Data Attributes
eefcf7-emercury
JS Globals
EMERCURY_EXTENSION_CF7_VERSIONEMERCURY_EXTENSION_CF7_PLUGIN_BASENAMEEMERCURY_EXTENSION_CF7_PLUGIN_NAMEEMERCURY_EXTENSION_CF7_PLUGIN_DIREMERCURY_EXTENSION_CF7_PLUGIN_URL
FAQ

Frequently Asked Questions about Emercury Extension For Contact Form 7