Multiple Files for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/multiple-files-for-contact-form-7

Multiple Files is addon for Contact Form 7

10 active installs v1.0 PHP + WP 4.2+ Updated Jul 4, 2017
contactcontact-formcontact-form-7-multiple-imagesformmultiple-files-for-contact-form-7
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Multiple Files for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

Multiple Files for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "multiple-files-for-contact-form-7" plugin, in version 1.0, presents a mixed security profile. On the positive side, the static analysis shows no known critical or high-severity vulnerabilities in its historical record and no detected taint flows. The plugin also demonstrates good practices in its SQL queries, exclusively using prepared statements, and a high percentage of properly escaped output. However, there are significant concerns. The complete absence of nonce checks and capability checks on any potential entry points is a major red flag, as it suggests that any functionality exposed could be executed by unauthenticated or unauthorized users. The presence of the `move_uploaded_file` function, a dangerous function, without any apparent authorization or input validation checks raises a potential risk for insecure file handling. The limited static analysis data, with zero entry points, might also indicate a very minimal plugin, which could mean the analysis is not comprehensive or that the plugin's functionality is extremely limited.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
  • Presence of dangerous function (move_uploaded_file)
  • Low attack surface data provided
Vulnerabilities
None known

Multiple Files for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Multiple Files for Contact Form 7 Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Multiple Files for Contact Form 7 Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
5
59 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

move_uploaded_fileif ( false === @move_uploaded_file( $file['tmp_name'], $new_file ) ) {multiple-files-for-contact-form-7.php:241

Output Escaping

92% escaped64 total outputs
Attack Surface

Multiple Files for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionadmin_noticesmultiple-files-for-contact-form-7.php:28
actionwpcf7_initmultiple-files-for-contact-form-7.php:31
filterwpcf7_form_enctypemultiple-files-for-contact-form-7.php:32
filterwpcf7_validate_multiplefilemultiple-files-for-contact-form-7.php:33
filterwpcf7_validate_multiplefile*multiple-files-for-contact-form-7.php:34
filterwpcf7_messagesmultiple-files-for-contact-form-7.php:35
actionwpcf7_admin_initmultiple-files-for-contact-form-7.php:36
actionwpcf7_admin_noticesmultiple-files-for-contact-form-7.php:37
filterwpcf7_mail_componentsmultiple-files-for-contact-form-7.php:38
Maintenance & Trust

Multiple Files for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedJul 4, 2017
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Multiple Files for Contact Form 7 Developer Profile

Dev Rathore

2 plugins · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Multiple Files for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Version Parameters
/multiple-files-for-contact-form-7/multiple-files-for-contact-form-7.php?ver=

HTML / DOM Fingerprints

CSS Classes
wpcf7-form-control-wrap
Data Attributes
multiple
Shortcode Output
<span class="wpcf7-form-control-wrap multiplefile<span class="wpcf7-form-control-wrap multiplefile*<input type="file" name="[]" multiple
FAQ

Frequently Asked Questions about Multiple Files for Contact Form 7