Magic Tooltips For Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/magic-tooltips-for-contact-form-7

Magic Tooltips For Contact Form 7 is a WordPress Contact Form 7 tooltip plugin that let's you add tooltips to the Contact Form 7 form fields.

700 active installs v1.0.33 PHP + WP 3.9+ Updated Mar 6, 2026
contact-form-7mobile-friendlyresponsivetooltips
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Magic Tooltips For Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Magic Tooltips For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 28d ago
Risk Assessment

The static analysis of 'magic-tooltips-for-contact-form-7' v1.0.33 indicates a generally good security posture regarding entry points and dangerous code patterns. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero-total attack surface. The code also demonstrates positive practices by exclusively using prepared statements for its SQL queries and not performing file operations or external HTTP requests. However, a significant concern is the low rate of output escaping, with only 20% of outputs being properly escaped. This leaves room for potential cross-site scripting (XSS) vulnerabilities if user-supplied data is ever processed and displayed without adequate sanitization, especially since no capability checks or nonce checks are present, which could have mitigated some risks if they were tied to entry points. The vulnerability history is completely clear, with no known CVEs or past issues. This, combined with the absence of critical taint flows and dangerous functions, suggests a well-developed and secure codebase to date. The lack of any identified vulnerabilities in the history is a strong positive, but the insufficient output escaping is a notable weakness that warrants attention.

Key Concerns

  • Low output escaping rate
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Magic Tooltips For Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Magic Tooltips For Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

20% escaped10 total outputs
Attack Surface

Magic Tooltips For Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_menucss-generator.php:3
actionadmin_initcss-generator.php:4
filterpre_update_option_mtfcf7_tooltip_generatorcss-generator.php:27
actionadmin_menuhelp.php:3
actionadmin_noticesplugin-index.php:63
actionadmin_menusettings.php:3
actionadmin_initsettings.php:4
filterpre_update_option_mtfcf7_settingssettings.php:38
Maintenance & Trust

Magic Tooltips For Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 6, 2026
PHP min version
Downloads16K

Community Trust

Rating94/100
Number of ratings3
Active installs700
Developer Profile

Magic Tooltips For Contact Form 7 Developer Profile

magicplugins

2 plugins · 710 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Magic Tooltips For Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/magic-tooltips-for-contact-form-7/assets/css/admin.css/wp-content/plugins/magic-tooltips-for-contact-form-7/assets/js/admin.js/wp-content/plugins/magic-tooltips-for-contact-form-7/assets/css/jquery.qtip.min.css/wp-content/plugins/magic-tooltips-for-contact-form-7/assets/css/custom.css/wp-content/plugins/magic-tooltips-for-contact-form-7/assets/js/jquery.qtip.js/wp-content/plugins/magic-tooltips-for-contact-form-7/assets/js/imagesloaded.pkgd.min.js/wp-content/plugins/magic-tooltips-for-contact-form-7/assets/js/custom.js/wp-content/plugins/magic-tooltips-for-contact-form-7/assets/css/font-awesome.min.css
Script Paths
/wp-content/plugins/magic-tooltips-for-contact-form-7/assets/js/admin.js/wp-content/plugins/magic-tooltips-for-contact-form-7/assets/js/jquery.qtip.js/wp-content/plugins/magic-tooltips-for-contact-form-7/assets/js/imagesloaded.pkgd.min.js/wp-content/plugins/magic-tooltips-for-contact-form-7/assets/js/custom.js
Version Parameters
magic-tooltips-for-contact-form-7/assets/js/admin.js?ver=magic-tooltips-for-contact-form-7/assets/css/font-awesome.min.css?ver=4.7

HTML / DOM Fingerprints

CSS Classes
mm-tooltip-cf7-containermm-tooltip-cf7-content
HTML Comments
Magic Tooltips For Contact Form 7Plugin Name: Magic Tooltips For Contact Form 7Version: 1.0.33Plugin URI: https://contactform7.magictooltips.com+8 more
Data Attributes
mtfcf7PluginCallout
JS Globals
mtfcf7mtfcf7_settings
FAQ

Frequently Asked Questions about Magic Tooltips For Contact Form 7