Identibyte for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/identibyte-for-contact-form-7

Make your forms intelligent. Detect and block signups and emails from disposable and fake email addresses in your Contact Form 7 forms.

0 active installs v1.0.0 PHP + WP 3.0.1+ Updated Unknown
cf7contact-form-7disposable-emailidentibytespam-blocker
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Identibyte for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Identibyte for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'identibyte-for-contact-form-7' plugin version 1.0.0 presents a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. The code also demonstrates good practices regarding SQL queries, with 100% using prepared statements, and includes a capability check. However, there are notable concerns. The taint analysis indicates that all analyzed flows (2 out of 2) involve unsanitized paths, although no critical or high severity issues were flagged in this specific analysis. Furthermore, only 25% of the outputs are properly escaped, leaving a significant portion potentially vulnerable to cross-site scripting (XSS) attacks. The presence of file operations without further context also warrants caution. The plugin's vulnerability history is clean, with no recorded CVEs, which is a strong positive indicator. Despite the lack of historical vulnerabilities, the identified issues in output escaping and taint analysis suggest potential weaknesses that could be exploited. Therefore, while the plugin has a small attack surface and good SQL practices, the unescaped outputs and unsanitized path flows require attention and mitigation.

Key Concerns

  • Unsanitized paths found in taint analysis
  • Low percentage of properly escaped output
  • File operations present without further context
Vulnerabilities
None known

Identibyte for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Identibyte for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped4 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
cf7_identibyte_validate_email_filter (identibyte.php:50)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Identibyte for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_initidentibyte.php:12
actionadmin_noticesidentibyte.php:19
filterwpcf7_validate_email*identibyte.php:42
filterwpcf7_validate_emailidentibyte.php:43
actionadmin_initidentibyte.php:101
actionadmin_menuidentibyte.php:102
Maintenance & Trust

Identibyte for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Identibyte for Contact Form 7 Developer Profile

identibyte

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Identibyte for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/identibyte-for-contact-form-7/img/identibyte-logo-120x120.png

HTML / DOM Fingerprints

Data Attributes
name="cf7_identibyte_token"
FAQ

Frequently Asked Questions about Identibyte for Contact Form 7