
GNA Contact Form 7 SMS Security & Risk Analysis
wordpress.org/plugins/gna-contact-form-7-smsSend SMS from your existing Contact Form 7 plugin using SMS Global.
Is GNA Contact Form 7 SMS Safe to Use in 2026?
Generally Safe
Score 85/100GNA Contact Form 7 SMS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gna-contact-form-7-sms" plugin v1.0.5 exhibits a mixed security posture. On the positive side, it has a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the plugin uses prepared statements for all SQL queries and has no file operations or external HTTP requests, which are excellent security practices. The absence of known CVEs and a clean vulnerability history are also positive indicators.
However, there are significant concerns regarding output escaping. With 19 total outputs and 0% properly escaped, this represents a major risk for cross-site scripting (XSS) vulnerabilities. Any user-supplied data displayed on the frontend without proper sanitization or escaping could be exploited. While the taint analysis shows no unsanitized flows, this might be due to the limited scope of the analysis or the lack of exploitable entry points for data to become tainted in the first place. The presence of nonce checks is good, but the complete absence of capability checks on any potential entry points is a concern if any were to be discovered or introduced in the future.
In conclusion, while the plugin has a strong foundation in terms of preventing SQL injection and limiting its attack surface, the critical lack of output escaping leaves it vulnerable to XSS attacks. This is the primary area requiring immediate attention. The absence of capability checks also represents a potential weakness if the plugin's functionality were to expand.
Key Concerns
- Unescaped output
- Missing capability checks
GNA Contact Form 7 SMS Security Vulnerabilities
GNA Contact Form 7 SMS Release Timeline
GNA Contact Form 7 SMS Code Analysis
Output Escaping
Data Flow Analysis
GNA Contact Form 7 SMS Attack Surface
WordPress Hooks 10
Maintenance & Trust
GNA Contact Form 7 SMS Maintenance & Trust
Maintenance Signals
Community Trust
GNA Contact Form 7 SMS Alternatives
DS CF7 Math Captcha
ds-cf7-math-captcha
"DS CF7 Math Captcha" is a math captcha with refresh captcha functionality to prevent unwanted spam for your contact form 7 plugin.
Awesome Contact Form7 for Elementor
awesome-contact-form7-for-elementor
Add Awesome Contact Form7 for Elementor with easy way.
Digital Signature For Contact Form 7
digital-signature-for-contact-form-7
Contact Form 7 Signature Addon making autographs of people who want to get an E-signature in the system. We build too easy to access and use for users …
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
Serial Number for Contact Form 7
serial-number-for-contact-form-7
Add-on for Contact Form 7 plugin. Add your own mail-tag to display the serial number.
GNA Contact Form 7 SMS Developer Profile
15 plugins · 300 total installs
How We Detect GNA Contact Form 7 SMS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gna-contact-form-7-sms/assets/css/gna-contact-form-7-sms-admin-styles.cssgna-contact-form-7-sms/style.css?ver=gna-contact-form-7-sms/admin/js/gna-contact-form-7-sms-admin-scripts.js?ver=HTML / DOM Fingerprints
data-g_cfs_form_idGNA_ContactForm7SMS_Admin