Mailster Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/mailster-contact-form-7

Create your Signup Forms with Contact Form 7 and allow users to signup to your newsletter.

1K active installs v1.6.0 PHP + WP 6.0+ Updated Nov 3, 2025
contact-form-7mailsternewslettersignup-form
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mailster Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Mailster Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "mailster-contact-form-7" plugin v1.6.0, based on the provided static analysis and vulnerability history, presents a generally strong security posture. The complete absence of identified dangerous functions, direct SQL queries without prepared statements, file operations, external HTTP requests, and a lack of reported CVEs are significant positive indicators. The zero attack surface from AJAX, REST API, shortcodes, and cron events, coupled with no recorded taint flows, suggests a well-contained and protected codebase.

However, the analysis does reveal some areas for improvement. The 40% of outputs that are not properly escaped represent a potential risk for cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is reflected directly in the output. Furthermore, the absence of nonce checks and capability checks on any potential entry points (though none were identified) could become a concern if new functionalities are added without adhering to WordPress security best practices.

In conclusion, while the plugin demonstrates excellent security hygiene in many critical areas, the unescaped output is a notable weakness that requires attention. The lack of historical vulnerabilities is a strong positive, but it's crucial to maintain vigilance, particularly concerning input sanitization and output escaping as the plugin evolves. The current version appears secure but could be further hardened by addressing the escaping issues.

Key Concerns

  • Unescaped output detected
Vulnerabilities
None known

Mailster Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Mailster Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

60% escaped10 total outputs
Attack Surface

Mailster Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitclasses\contactform.class.php:20
actionwpcf7_validateclasses\contactform.class.php:42
filterwpcf7_editor_panelsclasses\contactform.class.php:43
filterwpcf7_contact_form_propertiesclasses\contactform.class.php:44
actionwpcf7_save_contact_formclasses\contactform.class.php:45
actionwpcf7_skip_mailclasses\contactform.class.php:46
filterwpcf7_pre_construct_contact_form_propertiesclasses\contactform.class.php:47
actionwpcf7_mail_sentclasses\contactform.class.php:123
Maintenance & Trust

Mailster Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 3, 2025
PHP min version
Downloads27K

Community Trust

Rating100/100
Number of ratings4
Active installs1K
Developer Profile

Mailster Contact Form 7 Developer Profile

EverPress

28 plugins · 121K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
255 days
View full developer profile
Detection Fingerprints

How We Detect Mailster Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mailster-contact-form-7/assets/js/script.js/wp-content/plugins/mailster-contact-form-7/assets/css/style.css
Script Paths
/wp-content/plugins/mailster-contact-form-7/assets/js/script.js
Version Parameters
mailster-contact-form-7/assets/js/script.js?ver=mailster-contact-form-7/assets/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
mailster-cf7-settingscf7-mailster-remove-fieldcf7-mailster-add-fieldmailster-mapmailster-lists
Data Attributes
name="mailster[enabled]"name="mailster[checkbox]"name="mailster[checkboxfield]"name="mailster[gdpr_timestamp]"name="mailster[doubleoptin]"name="mailster[overwrite]"+4 more
FAQ

Frequently Asked Questions about Mailster Contact Form 7