EP Exporter for Contact Form 7 (CF7) Security & Risk Analysis

wordpress.org/plugins/ep-exporter-for-cf7

Smart and lightweight Contact Form 7 data exporter. Export your CF7 or CFDB7 submissions to CSV with advanced filtering options.

200 active installs v1.0.1 PHP 7.0+ WP 6.3+ Updated Oct 30, 2025
cf7cfdb7contact-form-7contact-form-7-databasecontact-form-export
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EP Exporter for Contact Form 7 (CF7) Safe to Use in 2026?

Generally Safe

Score 100/100

EP Exporter for Contact Form 7 (CF7) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "ep-exporter-for-cf7" plugin version 1.0.1 demonstrates a generally good security posture with robust implementation of security best practices. The plugin effectively utilizes prepared statements for its SQL queries (78%), employs proper output escaping in 96% of cases, and implements nonce and capability checks for all identified entry points, including its 3 AJAX handlers. The absence of external HTTP requests and bundled libraries further reduces the potential attack surface. The plugin also has no recorded vulnerability history, indicating a history of secure development.

Despite the strong overall security, the taint analysis revealed 2 flows with unsanitized paths classified as high severity. These specific flows represent a significant concern as they indicate potential vulnerabilities where user-supplied data could be processed in an unsafe manner. While the plugin has a clean vulnerability history, these taint findings suggest potential weaknesses that could be exploited if left unaddressed. The 2 identified flows with unsanitized paths are the primary risk. It is crucial to address these specific taint issues to maintain the plugin's secure standing.

In conclusion, "ep-exporter-for-cf7" v1.0.1 is largely secure due to its adherence to core WordPress security principles. However, the presence of high-severity taint flows necessitates immediate attention to prevent potential security incidents. The absence of historical vulnerabilities is a positive indicator, but these new findings highlight areas for improvement.

Key Concerns

  • High severity taint flow with unsanitized path
  • High severity taint flow with unsanitized path
Vulnerabilities
None known

EP Exporter for Contact Form 7 (CF7) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

EP Exporter for Contact Form 7 (CF7) Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
31 prepared
Unescaped Output
4
86 escaped
Nonce Checks
6
Capability Checks
6
File Operations
4
External Requests
0
Bundled Libraries
0

SQL Query Safety

78% prepared40 total queries

Output Escaping

96% escaped90 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ep_cf7_view_entry_page (views\admin-entry-page.php:11)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

EP Exporter for Contact Form 7 (CF7) Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 3

authwp_ajax_ep_cf7_export_dataincludes\admin\ajax-functions.php:8
authwp_ajax_ep_cf7_migrate_batchincludes\admin\ajax-functions.php:9
authwp_ajax_ep_cf7_dismiss_noticeincludes\admin\ajax-functions.php:10
WordPress Hooks 7
actionadmin_menuep-exporter-for-cf7.php:38
actionadmin_initep-exporter-for-cf7.php:39
actionadmin_enqueue_scriptsincludes\admin\enqueue-scripts.php:25
actionadmin_noticesincludes\admin\notices.php:29
actionadmin_noticesincludes\admin\notices.php:83
actionadmin_initincludes\admin\notices.php:95
actionwpcf7_before_send_mailincludes\frontend\functions.php:129
Maintenance & Trust

EP Exporter for Contact Form 7 (CF7) Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 30, 2025
PHP min version7.0
Downloads795

Community Trust

Rating100/100
Number of ratings1
Active installs200
Developer Profile

EP Exporter for Contact Form 7 (CF7) Developer Profile

EstudioPatagon

2 plugins · 200 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EP Exporter for Contact Form 7 (CF7)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ep-exporter-for-cf7/assets/css/admin.css/wp-content/plugins/ep-exporter-for-cf7/assets/js/admin.js
Script Paths
/wp-content/plugins/ep-exporter-for-cf7/assets/js/admin.js
Version Parameters
ep-exporter-for-cf7/assets/css/admin.css?ver=ep-exporter-for-cf7/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
ep-cf7-panelep-cf7-entry-viewep-entry-headerep-entry-metaep-entry-content
HTML Comments
<!-- start: .ep-cf7-entry-view --><!-- end: .ep-cf7-entry-view --><!-- start: .ep-entry-header --><!-- end: .ep-entry-header -->+2 more
Data Attributes
class="status-unread"class="status-read"
JS Globals
ep_cf7_ajax
FAQ

Frequently Asked Questions about EP Exporter for Contact Form 7 (CF7)