
PeproDev CF7 Database Security & Risk Analysis
wordpress.org/plugins/pepro-cf7-databaseReliable Solution to Save CF7 Submissions and Files, Works with CF7 v.5.9+
Is PeproDev CF7 Database Safe to Use in 2026?
Use With Caution
Score 67/100PeproDev CF7 Database has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'pepro-cf7-database' v2.0.0 plugin exhibits a mixed security posture. While the static analysis indicates a limited attack surface with no apparent direct entry points like AJAX handlers, REST API routes, or shortcodes, several concerning code signals warrant attention. The presence of the 'unserialize' function is a significant red flag, as it can lead to Remote Code Execution if used with untrusted input. The complete absence of prepared statements for all SQL queries is another critical weakness, exposing the plugin to SQL injection vulnerabilities. Furthermore, the low percentage of properly escaped output suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities.
The vulnerability history reveals a pattern of past security issues, with three known CVEs, one of which remains unpatched. The types of past vulnerabilities, including XSS and CSRF, align with the concerns raised by the static analysis, particularly the lack of proper output escaping and potential for unserialize-related vulnerabilities. The recent date of the last vulnerability, despite being in the future (which may indicate a data error or forecasting), emphasizes the ongoing nature of security concerns with this plugin. While the plugin has some strengths like nonce checks and capability checks, the identified weaknesses, especially the insecure handling of 'unserialize' and SQL queries, coupled with a history of high-severity vulnerabilities, make this plugin a considerable security risk.
Key Concerns
- Unpatched CVE
- Dangerous function: unserialize
- SQL queries without prepared statements
- Low percentage of proper output escaping
- High severity vulnerability in history
- Multiple past vulnerabilities
PeproDev CF7 Database Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
PeproDev CF7 Database <= 2.0.0 - Unauthenticated Stored Cross-Site Scripting
PeproDev CF7 Database <= 1.8.0 - Cross-Site Request Forgery
PeproDev CF7 Database <= 1.7.0 - Unauthenticated Stored Cross-Site Scripting via form submission
PeproDev CF7 Database Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
PeproDev CF7 Database Attack Surface
WordPress Hooks 8
Maintenance & Trust
PeproDev CF7 Database Maintenance & Trust
Maintenance Signals
Community Trust
PeproDev CF7 Database Alternatives
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
EP Exporter for Contact Form 7 (CF7)
ep-exporter-for-cf7
Smart and lightweight Contact Form 7 data exporter. Export your CF7 or CFDB7 submissions to CSV with advanced filtering options.
Contact Form 7 Database Manager Addon – CF7DBM
form-data-manager
Save contact form 7 submissions to the WP database with this CF7 addon. Never lose important messages, leads, and requests again.
Bridhy – No-code Drag & Drop Form Builder for Contact Form 7
bridhy-addons-for-contact-form-7
Build & style Contact Form 7 forms visually without writing any code. Bridhy also comes with essential addons to make your forms super powerful.
WP Contact Form 7 DB Handler
wp-contact-form-7-db-handler
Store all your contact form 7 submission and easily access it. you can also filter and export it!
PeproDev CF7 Database Developer Profile
6 plugins · 8K total installs
How We Detect PeproDev CF7 Database
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pepro-cf7-database/assets/css/admin.css/wp-content/plugins/pepro-cf7-database/assets/js/admin.js/wp-content/plugins/pepro-cf7-database/assets/js/cf7db-admin-notice.js/wp-content/plugins/pepro-cf7-database/assets/js/cf7db-contact-form-settings.js/wp-content/plugins/pepro-cf7-database/assets/js/cf7db-settings.js/wp-content/plugins/pepro-cf7-database/assets/css/style.css/wp-content/plugins/pepro-cf7-database/assets/js/custom.js/wp-content/plugins/pepro-cf7-database/assets/js/admin.js/wp-content/plugins/pepro-cf7-database/assets/js/cf7db-admin-notice.js/wp-content/plugins/pepro-cf7-database/assets/js/cf7db-contact-form-settings.js/wp-content/plugins/pepro-cf7-database/assets/js/cf7db-settings.js/wp-content/plugins/pepro-cf7-database/assets/js/custom.jspepro-cf7-database/assets/css/admin.css?ver=pepro-cf7-database/assets/js/admin.js?ver=pepro-cf7-database/assets/js/cf7db-admin-notice.js?ver=pepro-cf7-database/assets/js/cf7db-contact-form-settings.js?ver=pepro-cf7-database/assets/js/cf7db-settings.js?ver=pepro-cf7-database/assets/css/style.css?ver=pepro-cf7-database/assets/js/custom.js?ver=HTML / DOM Fingerprints
peprocf7db<!-- Pepro CF7 Database :: Unauthorized Access! -->id='peprocf7db'id='viewsavedsubmission'window.pepro_cf7_db_vars/wp-json/cf7db/v1/get-submissions/wp-json/cf7db/v1/get-submission/wp-json/cf7db/v1/delete-submission/wp-json/cf7db/v1/download-submissions/wp-json/cf7db/v1/download-attachments/wp-json/cf7db/v1/upload-settings/wp-json/cf7db/v1/get-settings/wp-json/cf7db/v1/delete-settings/wp-json/cf7db/v1/get-contact-forms/wp-json/cf7db/v1/get-cf7-settings/wp-json/cf7db/v1/save-cf7-settings/wp-json/cf7db/v1/delete-cf7-settings/wp-json/cf7db/v1/get-saved-data<div id='peprocf7db' class='postbox'><a class='button' id='viewsavedsubmission' target='_blank' href='