
CF7 LACRM Connector Security & Risk Analysis
wordpress.org/plugins/lacrm-connector-for-contact-form7Send your Contact Form 7 data directly to your Less Annoying CRM account.
Is CF7 LACRM Connector Safe to Use in 2026?
Generally Safe
Score 85/100CF7 LACRM Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The lacrm-connector-for-contact-form7 v1.2 plugin exhibits a generally good security posture with a limited attack surface and no recorded vulnerabilities. The absence of unpatched CVEs and a clean vulnerability history are positive indicators. Furthermore, the majority of output is properly escaped, and nonce and capability checks are present on entry points, demonstrating an awareness of basic WordPress security practices.
However, there are significant concerns within the static analysis. The presence of the `unserialize` function, particularly without clear indications of sanitization, poses a potential risk of arbitrary code execution if untrusted data is passed to it. Compounding this, 100% of SQL queries are not using prepared statements, which is a critical security flaw that can lead to SQL injection vulnerabilities. The single taint flow with unsanitized paths, though not critical or high severity in this analysis, is a warning sign that data flows are not being adequately controlled. The existence of file operations and external HTTP requests also warrants scrutiny, though the analysis doesn't explicitly flag these as problematic in this version.
In conclusion, while the plugin benefits from a clean vulnerability record and good practices in output escaping and auth checks, the use of `unserialize` and the complete lack of prepared statements for SQL queries represent substantial and potentially exploitable risks. These issues significantly detract from the overall security of the plugin and require immediate attention.
Key Concerns
- SQL queries not using prepared statements
- Presence of 'unserialize' function
- Taint flow with unsanitized paths
- File operations present
- External HTTP requests present
CF7 LACRM Connector Security Vulnerabilities
CF7 LACRM Connector Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
CF7 LACRM Connector Attack Surface
AJAX Handlers 3
WordPress Hooks 9
Maintenance & Trust
CF7 LACRM Connector Maintenance & Trust
Maintenance Signals
Community Trust
CF7 LACRM Connector Alternatives
GSheetConnector for CF7 – Connect Contact Form 7 to Google Sheets and Send Form Submissions in Real Time
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
Gsheet Contact Addons & ShortCode
shortcode-addons-for-google-sheet-api
Send your Contact Form 7 data directly to your Google Sheets spreadsheet API.
Contact Form 7 – Success Page Redirects
contact-form-7-success-page-redirects
An add-on for Contact Form 7 that provides a straightforward method to redirect visitors to success pages or thank you pages.
Contact Form 7 Modules
contact-form-7-modules
Contact Form 7 - Add useful modules such as hidden fields and "send all fields" to the Contact Form 7 plugin
Style Contact Form 7
customizer-block-cf7
This Contact Form 7 compatible Gutenberg Block automates CSS style generation allowing you to quickly design visually appealing contact forms.
CF7 LACRM Connector Developer Profile
3 plugins · 80 total installs
How We Detect CF7 LACRM Connector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lacrm-connector-for-contact-form7/assets/css/lacrm.css/wp-content/plugins/lacrm-connector-for-contact-form7/assets/js/lacrm.js/wp-content/plugins/lacrm-connector-for-contact-form7/assets/js/jquery.json.js/wp-content/plugins/lacrm-connector-for-contact-form7/assets/js/lacrm.js/wp-content/plugins/lacrm-connector-for-contact-form7/assets/js/jquery.json.jslacrm-connector-for-contact-form7/assets/css/lacrm.css?ver=lacrm-connector-for-contact-form7/assets/js/lacrm.js?ver=lacrm-connector-for-contact-form7/assets/js/jquery.json.js?ver=HTML / DOM Fingerprints
LACRM_CONNECTOR_VERSION