Lightbox for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/lightbox-for-contact-form-7

Shows Contact Form 7 in a fancy lightbox.

100 active installs v0.1 PHP + WP 4.6+ Updated Jun 25, 2018
contact-form-7fancyboxlightboxlightbox-for-contact-form-7popup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lightbox for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

Lightbox for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The plugin "lightbox-for-contact-form-7" v0.1 presents a seemingly strong security posture based on the provided static analysis and vulnerability history. The absence of any recorded CVEs, coupled with the code signals indicating no dangerous functions, no raw SQL queries, and 100% output escaping, suggests diligent development practices regarding common vulnerabilities. Furthermore, the analysis shows no identified taint flows, implying that data is being handled safely and not leading to exploitable conditions like remote code execution or cross-site scripting.

However, a significant concern arises from the lack of comprehensive security checks. The analysis reveals zero nonce checks and zero capability checks across all entry points. While there is only one entry point (a shortcode) and no AJAX or REST API endpoints to worry about in this version, the complete absence of these fundamental security mechanisms is a red flag. This indicates a reliance on other layers of security, which may not always be sufficient. A plugin that consistently exhibits such a pattern of missing basic security checks, even with a clean history, could become vulnerable if its attack surface expands or if its interaction with other WordPress components changes in future versions.

In conclusion, while "lightbox-for-contact-form-7" v0.1 has avoided known vulnerabilities and appears to handle its limited functionality securely from a code perspective, the complete omission of nonce and capability checks is a notable weakness. This oversight suggests a potential lack of awareness or adherence to standard WordPress security best practices for handling user input and actions. The plugin's current safety is heavily dependent on its limited attack surface and the absence of exploitable code patterns, rather than robust built-in security measures.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Lightbox for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Lightbox for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Lightbox for Contact Form 7 Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[cf7lightbox] lightbox-for-contact-form-7.php:35
Maintenance & Trust

Lightbox for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedJun 25, 2018
PHP min version
Downloads3K

Community Trust

Rating74/100
Number of ratings3
Active installs100
Developer Profile

Lightbox for Contact Form 7 Developer Profile

shimion

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lightbox for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lightbox-for-contact-form-7/assets/css/jquery.fancybox.min.css/wp-content/plugins/lightbox-for-contact-form-7/assets/js/jquery.fancybox.min.js/wp-content/plugins/lightbox-for-contact-form-7/assets/css/fancybox-style.css/wp-content/plugins/lightbox-for-contact-form-7/assets/js/fancybox-script.js

HTML / DOM Fingerprints

Data Attributes
data-fancyboxdata-src
Shortcode Output
<a data-fancybox data-src="#" href="javascript:;"></a><div id="" style="display: none;"><h3>
FAQ

Frequently Asked Questions about Lightbox for Contact Form 7