
Contact Form 7 minlength extension Security & Risk Analysis
wordpress.org/plugins/minimum-length-for-contact-form-7Extension to enable min-length on textfield(s) in Contact Form 7
Is Contact Form 7 minlength extension Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form 7 minlength extension has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "minimum-length-for-contact-form-7" plugin version 1.4.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any detected dangerous functions, unsanitized taint flows, or SQL queries that are not properly prepared is highly commendable. The plugin also demonstrates excellent output escaping practices, with a very high percentage of outputs being properly sanitized, minimizing the risk of cross-site scripting (XSS) vulnerabilities.
However, the analysis also highlights areas of potential concern, primarily related to the complete lack of security checks like nonce checks and capability checks across all entry points, which are reported as zero. While the attack surface itself is reported as zero, meaning no AJAX handlers, REST API routes, shortcodes, or cron events were found, the absence of these fundamental security mechanisms is a significant weakness. If any entry points were to be introduced or discovered later, they would be entirely unprotected.
The plugin's vulnerability history is spotless, with zero known CVEs. This, combined with the static analysis results, suggests a well-written and maintained plugin. Nonetheless, the missing security checks are a critical oversight that could lead to severe vulnerabilities if the plugin's architecture were to evolve or if unforeseen interaction vectors were discovered. In conclusion, the plugin is strong in its current implementation but carries inherent risks due to the lack of basic security controls on its (currently non-existent) entry points.
Key Concerns
- No nonce checks on any entry points
- No capability checks on any entry points
Contact Form 7 minlength extension Security Vulnerabilities
Contact Form 7 minlength extension Code Analysis
Output Escaping
Contact Form 7 minlength extension Attack Surface
WordPress Hooks 13
Maintenance & Trust
Contact Form 7 minlength extension Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 minlength extension Alternatives
Disable Flamingo Addressbook
disable-flamingo-addressbook
With this plugin activated, Flamingo will not add any data to its address book.
Inazo's flamingo automatically delete old messages
inazo-flamingo-automatically-delete-old-messages
This plugin help you to auto removed all information stored by flamingo.
User Role for Flamingo
user-role-for-flamingo
Configure special user role to access the flamingo contacts and messages wihtout admin permissions.
AC Advanced Flamingo Settings
ac-advanced-flamingo-settings
AC Advanced Flamingo Settings enhances and extends the functionality of the CF7 Flamingo plugin by adding customization options, import/export tools, …
Easy Panel for Contact Form 7
easy-panel-for-contact-form-7
Contact form submissions analytics dashboard. Understand all your submission statistics at a glance. Built with CF7 & Flamingo.
Contact Form 7 minlength extension Developer Profile
4 plugins · 1K total installs
How We Detect Contact Form 7 minlength extension
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
tg-nameonelineoptionclassvaluenumericdata-name="minlen"