EPE Formetto – PDF Attachments for Contact Forms Security & Risk Analysis

wordpress.org/plugins/epe-formetto-pdf-attachments-for-contact-forms

Automatically attach a clean PDF of Contact Form 7 submissions to email, simple, lightweight, and secure.

0 active installs v1.0.1 PHP 7.4+ WP 5.8+ Updated Feb 18, 2026
cf7-pdfcontact-form-7contact-form-pdfform-to-pdfpdf-attachment
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EPE Formetto – PDF Attachments for Contact Forms Safe to Use in 2026?

Generally Safe

Score 100/100

EPE Formetto – PDF Attachments for Contact Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "epe-formetto-pdf-attachments-for-contact-forms" plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points significantly limits the plugin's attack surface. Code analysis reveals a commitment to secure coding practices, with 100% of SQL queries using prepared statements and 99% of output being properly escaped. The presence of nonce and capability checks, although limited in number, further indicates an awareness of security fundamentals. The lack of any recorded CVEs, past or present, and no identified critical or high-severity taint flows are also positive indicators. However, the plugin does perform file operations and bundles the dompdf library, which, while not flagged as an issue here, warrants attention for potential future vulnerabilities or outdated versions. The limited number of entry points and absence of known vulnerabilities suggest a mature and well-maintained codebase, but vigilance regarding the bundled library and file operations is still recommended.

Key Concerns

  • Bundled library (dompdf)
  • File operations detected
Vulnerabilities
None known

EPE Formetto – PDF Attachments for Contact Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

EPE Formetto – PDF Attachments for Contact Forms Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

EPE Formetto – PDF Attachments for Contact Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
81 escaped
Nonce Checks
3
Capability Checks
3
File Operations
4
External Requests
0
Bundled Libraries
1

Bundled Libraries

dompdf

Output Escaping

99% escaped82 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
cf7_pdf_gen_download_pdf (epe-formetto-pdf-attachments.php:245)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

EPE Formetto – PDF Attachments for Contact Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionshutdownepe-formetto-pdf-attachments.php:73
actionwpcf7_before_send_mailepe-formetto-pdf-attachments.php:82
filterwpcf7_mail_componentsepe-formetto-pdf-attachments.php:124
filterwpcf7_mail_componentsepe-formetto-pdf-attachments.php:172
actionadmin_post_cf7_pdf_gen_download_pdfepe-formetto-pdf-attachments.php:243
actionadmin_post_cf7_pdf_gen_delete_pdfepe-formetto-pdf-attachments.php:322
actionadmin_enqueue_scriptsincludes/admin-settings.php:23
actionadmin_menuincludes/admin-settings.php:43
actionadmin_initincludes/admin-settings.php:58
Maintenance & Trust

EPE Formetto – PDF Attachments for Contact Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version7.4
Downloads204

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

EPE Formetto – PDF Attachments for Contact Forms Developer Profile

epetechsolutions

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EPE Formetto – PDF Attachments for Contact Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/epe-formetto-pdf-attachments-for-contact-forms/css/epe-formetto-pdf-attachments-style.css/wp-content/plugins/epe-formetto-pdf-attachments-for-contact-forms/js/epe-formetto-pdf-attachments.js
Script Paths
/wp-content/plugins/epe-formetto-pdf-attachments-for-contact-forms/js/epe-formetto-pdf-attachments.js
Version Parameters
epe-formetto-pdf-attachments-for-contact-forms/css/epe-formetto-pdf-attachments-style.css?ver=epe-formetto-pdf-attachments-for-contact-forms/js/epe-formetto-pdf-attachments.js?ver=

HTML / DOM Fingerprints

JS Globals
cf7_pdf_gen_is_cf7_activecf7_pdf_gen_is_enabledcf7_pdf_gen_handle_submissioncf7_pdf_gen_attach_pdf_to_mailcf7_pdf_gen_mail_template_normalization
FAQ

Frequently Asked Questions about EPE Formetto – PDF Attachments for Contact Forms