Leads Store Database Contact Form7 Security & Risk Analysis

wordpress.org/plugins/leads-store-database-contact-form7

Store and manage Contact Form 7 submissions in your database with easy export to CSV.

10 active installs v1.0.0 PHP 7.4+ WP 6.2+ Updated Jan 9, 2026
cf7contact-form-7databasesavesubmissions
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Leads Store Database Contact Form7 Safe to Use in 2026?

Generally Safe

Score 100/100

Leads Store Database Contact Form7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "leads-store-database-contact-form7" plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified CVEs, combined with 100% use of prepared statements for SQL queries and proper output escaping, indicates good development practices in these critical areas. The plugin also demonstrates an awareness of security by including nonce and capability checks, and crucially, an absence of external HTTP requests, which significantly reduces the attack surface for certain types of vulnerabilities. Taint analysis further supports this, with no unsanitized flows detected.

However, a few minor areas warrant attention. The presence of a single file operation, while not inherently malicious, represents a potential entry point that could be exploited if not handled with extreme care. The lack of any identified AJAX handlers, REST API routes, or shortcodes means the plugin has a very small attack surface in terms of direct user interaction points, which is a positive, but it also means there are zero unprotected entry points, which is ideal. The vulnerability history being entirely clean is a very positive sign, suggesting a stable and well-maintained codebase or a plugin that has not attracted attention from attackers, which is common for newer or less complex plugins.

In conclusion, the plugin appears to be developed with security in mind, adhering to many best practices. The primary strength lies in its secure handling of database interactions and output. The main weakness, albeit minor, is the single file operation, which should be monitored. The clean vulnerability history is a significant strength. Overall, the risk associated with this plugin at v1.0.0 appears to be low.

Key Concerns

  • File operations without explicit checks
Vulnerabilities
None known

Leads Store Database Contact Form7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Leads Store Database Contact Form7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
8 prepared
Unescaped Output
0
39 escaped
Nonce Checks
2
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared8 total queries

Output Escaping

100% escaped39 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
render_submissions_page (includes\class-admin-page.php:33)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Leads Store Database Contact Form7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuincludes\class-admin-page.php:9
actionadmin_enqueue_scriptsincludes\class-admin-page.php:10
actionadmin_initincludes\class-export-page.php:9
actionwpcf7_before_send_mailleads-store-database-contact-form7.php:33
Maintenance & Trust

Leads Store Database Contact Form7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 9, 2026
PHP min version7.4
Downloads134

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Leads Store Database Contact Form7 Developer Profile

melonwebstudio

2 plugins · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Leads Store Database Contact Form7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/leads-store-database-contact-form7/css/admin-style.css/wp-content/plugins/leads-store-database-contact-form7/js/admin-script.js
Script Paths
/wp-content/plugins/leads-store-database-contact-form7/js/admin-script.js
Version Parameters
leads-store-database-contact-form7/css/admin-style.css?ver=leads-store-database-contact-form7/js/admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
mwscl-db-filtersmwscl-support-sectionshow-lead-details
Data Attributes
data-submission
FAQ

Frequently Asked Questions about Leads Store Database Contact Form7