
Generate PDF using Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/generate-pdf-using-contact-form-7Generate PDF using Contact Form 7 Plugin makes it simple to create PDFs for downloads, viewing, or sending as attachments after form submissions.
Is Generate PDF using Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 96/100Generate PDF using Contact Form 7 has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the 'generate-pdf-using-contact-form-7' plugin v4.1.6 reveals a generally good security posture in terms of direct code vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with exposed entry points is a strong positive. The plugin also demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage of output escaping. Nonce and capability checks are present, indicating awareness of common web security principles. However, the history of known vulnerabilities, including 3 CVEs with 2 classified as high severity and 1 as medium, is a significant concern. The common vulnerability types (CSRF and XSS) suggest that the plugin has historically struggled with proper input validation and state management, even if the current version's static analysis doesn't immediately flag these issues. The presence of file operations also warrants careful monitoring, though the static analysis doesn't indicate any immediate risks.
Key Concerns
- Multiple past high severity vulnerabilities (CVEs)
- One past medium severity vulnerability (CVE)
- Two file operations detected
- 9% of output not properly escaped
Generate PDF using Contact Form 7 Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Generate PDF using Contact Form 7 <= 4.1.2 - Cross-Site Request Forgery to Arbitrary File Deletion
Generate PDF using Contact Form 7 <= 4.1.2 - Cross-Site Request Forgery to Arbitrary File Upload
Generate PDF using Contact Form 7 <= 3.5 - Authenticated (Administrator+) Stored Cross-Site Scripting
Generate PDF using Contact Form 7 Code Analysis
Output Escaping
Data Flow Analysis
Generate PDF using Contact Form 7 Attack Surface
WordPress Hooks 21
Maintenance & Trust
Generate PDF using Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Generate PDF using Contact Form 7 Alternatives
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
PDF Forms Filler for CF7
pdf-forms-for-contact-form-7
Build Contact Form 7 forms from PDF forms. Get PDFs auto-filled and attached to email messages and/or website responses on form submission.
Creative Mail – Easier WordPress & WooCommerce Email Marketing
creative-mail-by-constant-contact
Creative Mail was designed specifically for WordPress and WooCommerce. Our intelligent (and super fun) email editor simplifies email marketing campaig …
HTML Forms – Simple WordPress Forms Plugin
html-forms
A simpler, faster, and smarter WordPress forms plugin.
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress
wpzoom-forms
Drag & drop contact form builder for WordPress. Create contact forms, custom forms, email forms with spam protection. Works with Elementor, shortcodes
Generate PDF using Contact Form 7 Developer Profile
18 plugins · 7K total installs
How We Detect Generate PDF using Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/generate-pdf-using-contact-form-7/assets/css/cf7-pdf-generation-admin-min.css/wp-content/plugins/generate-pdf-using-contact-form-7/assets/css/cf7-pdf-generation-codemirror-min.css/wp-content/plugins/generate-pdf-using-contact-form-7/assets/css/cf7-pdf-generation-3024-night-min.css/wp-content/plugins/generate-pdf-using-contact-form-7/assets/css/cf7-pdf-jquery-ui-min.css/wp-content/plugins/generate-pdf-using-contact-form-7/assets/js/cf7-pdf-generation-codemirror-min.js/wp-content/plugins/generate-pdf-using-contact-form-7/assets/js/cf7-pdf-generation-codemirror-javascript-min.js/wp-content/plugins/generate-pdf-using-contact-form-7/assets/js/cf7-pdf-generation-admin-min.js/wp-content/plugins/generate-pdf-using-contact-form-7/assets/js/cf7-pdf-generation-admin-upload-script-min.jsassets/js/cf7-pdf-generation-codemirror-min.jsassets/js/cf7-pdf-generation-codemirror-javascript-min.jsassets/js/cf7-pdf-generation-admin-min.jsassets/js/cf7-pdf-generation-admin-upload-script-min.jscf7-pdf-generation-admin-min.css?ver=cf7-pdf-generation-codemirror-min.css?ver=cf7-pdf-generation-3024-night-min.css?ver=cf7-pdf-jquery-ui-min.css?ver=cf7-pdf-generation-codemirror-min.js?ver=cf7-pdf-generation-codemirror-javascript-min.js?ver=cf7-pdf-generation-admin-min.js?ver=cf7-pdf-generation-admin-upload-script-min.js?ver=HTML / DOM Fingerprints
cf7-pdf-settings<!-- The main plugin class --><!-- The admin class --><!-- The front end class --><!-- This is the PDF template -->+1 moredata-cf7-pdf-form-iddata-cf7-pdf-titledata-cf7-pdf-filenamedata-cf7-pdf-orientationdata-cf7-pdf-pagesizedata-cf7-pdf-margin-top+7 morecf7_pdf_generation_object[cf7-pdf-form-generator]