
EP Exporter for Contact Form 7 (CF7) Security & Risk Analysis
wordpress.org/plugins/ep-exporter-for-cf7Smart and lightweight Contact Form 7 data exporter. Export your CF7 or CFDB7 submissions to CSV with advanced filtering options.
Is EP Exporter for Contact Form 7 (CF7) Safe to Use in 2026?
Generally Safe
Score 100/100EP Exporter for Contact Form 7 (CF7) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ep-exporter-for-cf7" plugin version 1.0.1 demonstrates a generally good security posture with robust implementation of security best practices. The plugin effectively utilizes prepared statements for its SQL queries (78%), employs proper output escaping in 96% of cases, and implements nonce and capability checks for all identified entry points, including its 3 AJAX handlers. The absence of external HTTP requests and bundled libraries further reduces the potential attack surface. The plugin also has no recorded vulnerability history, indicating a history of secure development.
Despite the strong overall security, the taint analysis revealed 2 flows with unsanitized paths classified as high severity. These specific flows represent a significant concern as they indicate potential vulnerabilities where user-supplied data could be processed in an unsafe manner. While the plugin has a clean vulnerability history, these taint findings suggest potential weaknesses that could be exploited if left unaddressed. The 2 identified flows with unsanitized paths are the primary risk. It is crucial to address these specific taint issues to maintain the plugin's secure standing.
In conclusion, "ep-exporter-for-cf7" v1.0.1 is largely secure due to its adherence to core WordPress security principles. However, the presence of high-severity taint flows necessitates immediate attention to prevent potential security incidents. The absence of historical vulnerabilities is a positive indicator, but these new findings highlight areas for improvement.
Key Concerns
- High severity taint flow with unsanitized path
- High severity taint flow with unsanitized path
EP Exporter for Contact Form 7 (CF7) Security Vulnerabilities
EP Exporter for Contact Form 7 (CF7) Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
EP Exporter for Contact Form 7 (CF7) Attack Surface
AJAX Handlers 3
WordPress Hooks 7
Maintenance & Trust
EP Exporter for Contact Form 7 (CF7) Maintenance & Trust
Maintenance Signals
Community Trust
EP Exporter for Contact Form 7 (CF7) Alternatives
WPSyncSheets For Contact Form 7 – CF7 Google Sheets Connector & Save to Database
contactsheets-lite
Connect Contact Form 7 submissions to Google Sheets to sync your form entries and save all cf7 forms submitted data to the database.
Contact Form 7 Database Manager Addon – CF7DBM
form-data-manager
Save contact form 7 submissions to the WP database with this CF7 addon. Never lose important messages, leads, and requests again.
PeproDev CF7 Database
pepro-cf7-database
Reliable Solution to Save CF7 Submissions and Files, Works with CF7 v.5.9+
WP Contact Form 7 DB Handler
wp-contact-form-7-db-handler
Store all your contact form 7 submission and easily access it. you can also filter and export it!
Contact Form 7 Save to Database (Add-on for CF7)
cf7-save-to-database
Contact Form 7 Save to Database helps you add multi-step for your form. This is the best solution to keep the form as simple as possible to your visit …
EP Exporter for Contact Form 7 (CF7) Developer Profile
2 plugins · 200 total installs
How We Detect EP Exporter for Contact Form 7 (CF7)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ep-exporter-for-cf7/assets/css/admin.css/wp-content/plugins/ep-exporter-for-cf7/assets/js/admin.js/wp-content/plugins/ep-exporter-for-cf7/assets/js/admin.jsep-exporter-for-cf7/assets/css/admin.css?ver=ep-exporter-for-cf7/assets/js/admin.js?ver=HTML / DOM Fingerprints
ep-cf7-panelep-cf7-entry-viewep-entry-headerep-entry-metaep-entry-content<!-- start: .ep-cf7-entry-view --><!-- end: .ep-cf7-entry-view --><!-- start: .ep-entry-header --><!-- end: .ep-entry-header -->+2 moreclass="status-unread"class="status-read"ep_cf7_ajax