
EngageBay Add-on For Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/engagebay-add-on-for-contact-form-7Send Contact Form 7 submissions to EngageBay automcatically using this plugin. Link any field type with EngageBay including custom fields.
Is EngageBay Add-on For Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 92/100EngageBay Add-on For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "engagebay-add-on-for-contact-form-7" v1.9.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no identified dangerous functions, all SQL queries utilize prepared statements, and there are no recorded CVEs, suggesting a good track record and adherence to secure coding practices for database interactions. However, several areas raise concerns. The absence of nonce checks and capability checks, coupled with a high percentage of unsanitized taint flows (3 out of 3 analyzed), indicates potential vulnerabilities where user-supplied data might not be properly validated or authorized before being processed. Furthermore, while the attack surface appears small with zero identified entry points like AJAX handlers or REST API routes, this may be misleading if the plugin relies on external interactions or indirect input handling not captured in this analysis. The file operation and external HTTP requests also warrant scrutiny to ensure they are not being exploited.
Key Concerns
- Unsanitized taint flows detected
- No nonce checks detected
- No capability checks detected
- Significant portion of output not escaped
- File operations present
- External HTTP requests present
EngageBay Add-on For Contact Form 7 Security Vulnerabilities
EngageBay Add-on For Contact Form 7 Release Timeline
EngageBay Add-on For Contact Form 7 Code Analysis
Output Escaping
Data Flow Analysis
EngageBay Add-on For Contact Form 7 Attack Surface
WordPress Hooks 6
Maintenance & Trust
EngageBay Add-on For Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
EngageBay Add-on For Contact Form 7 Alternatives
Contact Form by Supsystic
contact-form-by-supsystic
Contact Form Builder with drag-and-drop editor to create responsive, mobile ready contact forms in a second. Custom fields and contact form templates
Contact Form Generator : Creative form builder for WordPress
contact-form-generator
Contact Form Generator is a creative and powerful contact form builder! You will get ready-to-use forms in 5 minutes!
NM Contact Forms
nm-contact-forms
Contact form plugin. NM contact forms allow you simple contact form integration with two built-in anti-spam solutions. Supports get variable.
DigitSix Simple Contact Form
digitsix-simple-contact-form
DigitSix Simple Contact Form is a simple solution for those who need simple contact forms for their website.
Contact Blaster
contact-blaster
Simplest contact forms ever. Two easy ways to use:
EngageBay Add-on For Contact Form 7 Developer Profile
7 plugins · 430 total installs
How We Detect EngageBay Add-on For Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/engagebay-add-on-for-contact-form-7/assets/css/styles.css/wp-content/plugins/engagebay-add-on-for-contact-form-7/assets/js/scripts.js/wp-content/plugins/engagebay-add-on-for-contact-form-7/assets/js/refresh.jsassets/js/scripts.jsassets/js/refresh.jsengagebay-add-on-for-contact-form-7/assets/css/styles.css?ver=engagebay-add-on-for-contact-form-7/assets/js/scripts.js?ver=HTML / DOM Fingerprints
cf7ebi-stylesengagebay-marketing-softwaredata-cf7ebi-noncecf7ebi_data