Mis Leads – Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/mis-leads-contact-form-7

Contecta formularios de Contact Form 7 con Mis Leads.

10 active installs v1.1 PHP + WP 3.0.1+ Updated Sep 13, 2017
conctactcontact-formformleads
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mis Leads – Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

Mis Leads – Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "mis-leads-contact-form-7" v1.1 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of any known CVEs, coupled with zero critical or high severity issues in taint analysis, suggests a robust development process. The fact that all SQL queries use prepared statements is a significant strength, mitigating common SQL injection risks. However, the low percentage of properly escaped output (29%) is a notable concern. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, where user-supplied data might be rendered directly in the browser without proper sanitization, allowing malicious scripts to be executed.

While the plugin has a clean vulnerability history and no recorded past issues, the limited number of analyzed flows in the taint analysis (2 total, 0 with unsanitized paths) and the presence of a nonce check alongside zero capability checks mean that the attack surface, though small in terms of entry points, might not be fully stress-tested for all potential injection vectors or privilege escalation scenarios. The lack of exploitable signals in the static analysis is encouraging, but the output escaping weakness warrants attention to ensure user-provided data is always handled securely.

Key Concerns

  • Low output escaping rate
Vulnerabilities
None known

Mis Leads – Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Mis Leads – Contact Form 7 Release Timeline

v1.0
Code Analysis
Analyzed Apr 16, 2026

Mis Leads – Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
2 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

29% escaped7 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
save_config (includes/class.misleads-cf7.php:167)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Mis Leads – Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitincludes/class.misleads-cf7.php:58
actionadmin_menuincludes/class.misleads-cf7.php:60
actioninitincludes/class.misleads-cf7.php:62
actionmisleads_cf7_noticesincludes/class.misleads-cf7.php:64
actionadmin_enqueue_scriptsincludes/class.misleads-cf7.php:73
actionwp_enqueue_scriptsincludes/class.misleads-cf7.php:75
Maintenance & Trust

Mis Leads – Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedSep 13, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Mis Leads – Contact Form 7 Developer Profile

Oscar Alvarez

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mis Leads – Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mis-leads-contact-form-7/js/admin.js/wp-content/plugins/mis-leads-contact-form-7/js/front.js
Script Paths
/wp-content/plugins/mis-leads-contact-form-7/js/admin.js/wp-content/plugins/mis-leads-contact-form-7/js/front.js
Version Parameters
mis-leads-contact-form-7/js/admin.js?ver=mis-leads-contact-form-7/js/front.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Testing Contact Form Hook --><!-- Version 1.0 --><!-- Backend Scripts --><!-- Frontend Scripts -->+9 more
JS Globals
misLeadsCF7misLeadsCF7.option_namemisLeadsCF7.fieldsmisLeadsCF7.productsmisLeadsCF7.sourcemisLeadsCF7.cliente+21 more
REST Endpoints
/misleads/api/lead?
FAQ

Frequently Asked Questions about Mis Leads – Contact Form 7