Integration between GrooveHQ and CF7 Security & Risk Analysis

wordpress.org/plugins/integration-between-groovehq-and-cf7

Plugin allows you to choose contact forms that send requests directly to GrooveHQ inbox instead to email.

10 active installs v1.0.2 PHP + WP 4.3+ Updated Sep 25, 2015
contactcontact-form-7formgroovegroovehq
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Integration between GrooveHQ and CF7 Safe to Use in 2026?

Generally Safe

Score 85/100

Integration between GrooveHQ and CF7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The plugin 'integration-between-groovehq-and-cf7' v1.0.2 exhibits a strong adherence to some security best practices, particularly in its handling of SQL queries, which are entirely performed using prepared statements. Furthermore, the absence of known CVEs and a clean vulnerability history suggests a generally stable and well-maintained codebase. The plugin also demonstrates a minimal attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks.

However, significant security concerns arise from the complete lack of output escaping for all identified output points. This means that any data rendered by the plugin, if it originates from user input or external sources, is vulnerable to Cross-Site Scripting (XSS) attacks. The absence of nonce checks and capability checks, coupled with the use of dangerous functions and file operations, indicates a lack of robust authorization and input validation, which could be exploited if any user-controlled data enters these code paths. The presence of external HTTP requests without clear indication of sanitization or validation also warrants caution.

While the plugin has a clean history and a small attack surface, the critical weakness in output escaping and the general lack of authorization checks present a tangible risk. The development team appears to have focused on database security, but has overlooked output sanitization and authorization mechanisms, creating a potential avenue for attackers to compromise user sessions or inject malicious content.

Key Concerns

  • 0% output escaping
  • 0 capability checks
  • 0 nonce checks
  • Dangerous functions present
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

Integration between GrooveHQ and CF7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Integration between GrooveHQ and CF7 Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Integration between GrooveHQ and CF7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
3
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

Integration between GrooveHQ and CF7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwpcf7_before_send_mailindex.php:19
actionadmin_menuindex.php:20
actionadmin_initindex.php:21
filterwpcf7_skip_mailindex.php:24
filterwp_mail_content_typeindex.php:70
Maintenance & Trust

Integration between GrooveHQ and CF7 Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedSep 25, 2015
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Integration between GrooveHQ and CF7 Developer Profile

Niteo

4 plugins · 20K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Integration between GrooveHQ and CF7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integration-between-groovehq-and-cf7/assets/css/settings.css/wp-content/plugins/integration-between-groovehq-and-cf7/assets/js/settings.js
Script Paths
/wp-content/plugins/integration-between-groovehq-and-cf7/assets/js/settings.js
Version Parameters
integration-between-groovehq-and-cf7/assets/css/settings.css?ver=integration-between-groovehq-and-cf7/assets/js/settings.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Integration between GrooveHQ and CF7