
Identibyte for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/identibyte-for-contact-form-7Make your forms intelligent. Detect and block signups and emails from disposable and fake email addresses in your Contact Form 7 forms.
Is Identibyte for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100Identibyte for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'identibyte-for-contact-form-7' plugin version 1.0.0 presents a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. The code also demonstrates good practices regarding SQL queries, with 100% using prepared statements, and includes a capability check. However, there are notable concerns. The taint analysis indicates that all analyzed flows (2 out of 2) involve unsanitized paths, although no critical or high severity issues were flagged in this specific analysis. Furthermore, only 25% of the outputs are properly escaped, leaving a significant portion potentially vulnerable to cross-site scripting (XSS) attacks. The presence of file operations without further context also warrants caution. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strong positive indicator. Despite the lack of historical vulnerabilities, the identified issues in output escaping and taint analysis suggest potential weaknesses that could be exploited. Therefore, while the plugin has a small attack surface and good SQL practices, the unescaped outputs and unsanitized path flows require attention and mitigation.
Key Concerns
- Unsanitized paths found in taint analysis
- Low percentage of properly escaped output
- File operations present without further context
Identibyte for Contact Form 7 Security Vulnerabilities
Identibyte for Contact Form 7 Code Analysis
Output Escaping
Data Flow Analysis
Identibyte for Contact Form 7 Attack Surface
WordPress Hooks 6
Maintenance & Trust
Identibyte for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Identibyte for Contact Form 7 Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Advanced Contact form 7 DB
advanced-cf7-db
Save all contact form 7 form submitted data to the database, View, Ordering, Change field labels and Import/Export data using CSV.
Connect Contact Form 7 and Mailchimp
contact-form-7-mailchimp-extension
Connect Contact Form 7 to Mailchimp. Automatically sync form submissions to your Mailchimp audiences with merge field mapping, double opt-in, and opt- …
Contact Form 7 Multi-Step Forms
contact-form-7-multi-step-module
Enables the Contact Form 7 plugin to create multi-page, multi-step forms.
Identibyte for Contact Form 7 Developer Profile
1 plugin · 0 total installs
How We Detect Identibyte for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/identibyte-for-contact-form-7/img/identibyte-logo-120x120.pngHTML / DOM Fingerprints
name="cf7_identibyte_token"