Integrate AWeber and Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/integrate-aweber-and-contact-form-7

Integrate AWeber and Contact Form 7. Connect your forms to lists and save submitted data directly to your AWeber account.

10 active installs v1.0.1 PHP + WP 3.0.1+ Updated Mar 10, 2020
awebercf7-awebercf7-aweber-extensioncf7-aweber-integrationcontact-form-7
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Integrate AWeber and Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

Integrate AWeber and Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

This plugin, "integrate-aweber-and-contact-form-7" v1.0.1, presents a significant security risk primarily due to its unprotected AJAX handlers. The static analysis reveals five AJAX handlers, all of which lack authentication checks. This means any authenticated WordPress user, regardless of their role or permissions, could potentially trigger these functions. While there are no recorded vulnerabilities in its history and the plugin utilizes prepared statements for SQL queries and a reasonable percentage of output escaping, the absence of authentication on such a large portion of its entry points is a major concern.

The taint analysis indicates that all analyzed flows have unsanitized paths, though no critical or high-severity issues were flagged directly from this. This could be a consequence of the missing authentication checks on the AJAX handlers, where user-supplied data might be processed without proper validation or authorization. The lack of nonce checks further exacerbates this risk, as it provides an additional layer of protection that is completely missing from the identified entry points.

Overall, while the plugin shows some good practices like prepared SQL statements, the critical weakness lies in its attack surface. The unprotected AJAX handlers create a broad and easily exploitable entry point for malicious actors. The vulnerability history being clean is a positive sign, but it does not mitigate the immediate risks posed by the current code's lack of essential security measures. Users should exercise extreme caution or seek an updated version with these security flaws addressed.

Key Concerns

  • AJAX handlers without authentication
  • AJAX handlers without nonces
  • Unsanitized paths in taint flows
  • Output escaping below optimal (65%)
Vulnerabilities
None known

Integrate AWeber and Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Integrate AWeber and Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
33 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

65% escaped51 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

5 flows5 with unsanitized paths
awbc_get_accounts (api\class-awb-cf7-api.php:19)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
5 unprotected

Integrate AWeber and Contact Form 7 Attack Surface

Entry Points5
Unprotected5

AJAX Handlers 5

authwp_ajax_awbc_get_access_tokenincludes\class-awb-cf7.php:148
authwp_ajax_awbc_revoke_authincludes\class-awb-cf7.php:149
authwp_ajax_awbc_get_accountsincludes\class-awb-cf7.php:152
authwp_ajax_awbc_get_listsincludes\class-awb-cf7.php:153
authwp_ajax_awbc_connect_listincludes\class-awb-cf7.php:154
WordPress Hooks 6
actionplugins_loadedincludes\class-awb-cf7.php:128
actionadmin_enqueue_scriptsincludes\class-awb-cf7.php:141
actionadmin_enqueue_scriptsincludes\class-awb-cf7.php:142
actionwpcf7_editor_panelsincludes\class-awb-cf7.php:145
actionwpcf7_save_contact_formincludes\class-awb-cf7.php:156
actionwpcf7_before_send_mailincludes\class-awb-cf7.php:157
Maintenance & Trust

Integrate AWeber and Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMar 10, 2020
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Integrate AWeber and Contact Form 7 Developer Profile

Darpan Kulkarni

2 plugins · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Integrate AWeber and Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integrate-aweber-and-contact-form-7/admin/css/awb-cf7-admin.css/wp-content/plugins/integrate-aweber-and-contact-form-7/admin/js/awb-cf7-admin.js
Script Paths
admin/js/awb-cf7-admin.js
Version Parameters
awb-cf7-admin.css?ver=awb-cf7-admin.js?ver=

HTML / DOM Fingerprints

JS Globals
awbc
FAQ

Frequently Asked Questions about Integrate AWeber and Contact Form 7