Lazyload for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/fsdpcfl-contact-form-lazyload

Lazyload for Contact Form 7 is a lightweight WordPress plugin designed to improve your website's performance by lazyloading Contact Form 7.

50 active installs v2.0.2 PHP 7.4+ WP 6.5+ Updated Feb 19, 2025
cf7contact-form-7contact-form-7-lazyloadlazyload-formwpcf7
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lazyload for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 92/100

Lazyload for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "fsdpcfl-contact-form-lazyload" plugin version 2.0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs and a clean vulnerability history indicate a well-maintained or historically secure codebase. The code analysis reveals a very limited attack surface with only one shortcode and no AJAX handlers or REST API routes that are unprotected. Furthermore, the plugin demonstrates good coding practices with 100% of SQL queries using prepared statements and a high percentage of output escaping. The presence of a nonce check also suggests an attempt to mitigate certain types of vulnerabilities.

Key Concerns

  • Capability checks are missing on entry points
  • High percentage of output escaping, but not 100%
Vulnerabilities
None known

Lazyload for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Lazyload for Contact Form 7 Release Timeline

v2.0.2Current
v2.0.1
v2.0.0
Code Analysis
Analyzed Mar 16, 2026

Lazyload for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
16 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped17 total outputs
Attack Surface

Lazyload for Contact Form 7 Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[lazy-contact-form-7] includes\form-shortcode.php:34
WordPress Hooks 11
actionadmin_noticesadmin\functions.php:7
actionadmin_initadmin\functions.php:10
actionwp_loadedincludes\form-loader.php:4
filterwpcf7_load_jsincludes\remove-cf7.php:5
filterwpcf7_load_cssincludes\remove-cf7.php:6
actionwp_print_scriptsincludes\remove-cf7.php:8
filterthe_contentincludes\replace-shortcode.php:5
actionwp_enqueue_scriptsincludes\scripts.php:4
actionwp_enqueue_scriptsincludes\scripts.php:9
actionwp_enqueue_scriptstemplates\form.php:7
actionadmin_inittemplates\form.php:35
Maintenance & Trust

Lazyload for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 19, 2025
PHP min version7.4
Downloads869

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

Lazyload for Contact Form 7 Developer Profile

56 Degrees

4 plugins · 2K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lazyload for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fsdpcfl-contact-form-lazyload/build/index.js
Script Paths
/wp-content/plugins/fsdpcfl-contact-form-lazyload/build/index.js
Version Parameters
fsdpcfl-contact-form-lazyload/build/index.js?ver=fsdpcfl-styles?ver=

HTML / DOM Fingerprints

CSS Classes
fsdpcfl-iframefsdpcfl-loaderfsdpcfl-loader.activefsdpcfl-form-page
Data Attributes
data-fsdpcfl-root-margindata-fsdpcfl-observedata-fsdpcfl-src
Shortcode Output
<div class="fsdpcfl-iframe"><iframe style="width: 100%;" data-fsdpcfl-src="
FAQ

Frequently Asked Questions about Lazyload for Contact Form 7