PiWeb Alerts for Contact Form 7 in Telegram Security & Risk Analysis

wordpress.org/plugins/piwebsolution-alerts-contact-form-7-telegram

Send Telegram alerts for Contact Form 7 submissions, including file attachments, to one or more chats, groups, or channels.

0 active installs v1.0.2 PHP 7.4+ WP 5.0+ Updated Mar 4, 2026
attachmentscontact-form-7notificationstelegram
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PiWeb Alerts for Contact Form 7 in Telegram Safe to Use in 2026?

Generally Safe

Score 100/100

PiWeb Alerts for Contact Form 7 in Telegram has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "piwebsolution-alerts-contact-form-7-telegram" v1.0.2 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of detected dangerous functions, SQL injection vulnerabilities due to prepared statements, and universally escaped output are excellent indicators of good coding practices. Furthermore, the lack of recorded CVEs and a clean vulnerability history suggests a well-maintained and secure plugin.

However, a few areas warrant attention. The presence of file operations and external HTTP requests, while not inherently insecure, represents potential vectors for attack if not handled with extreme care and robust sanitization. The absence of capability checks on any entry points is a significant concern, as it implies that any authenticated user, regardless of their role, could potentially interact with plugin functionalities. While the total attack surface is reported as zero, this seems contradictory to the presence of file operations and external HTTP requests, which typically require some form of handler. The taint analysis reporting zero flows could be due to a limited scope of analysis or an absence of identifiable sensitive data flows, but it's important to acknowledge that this doesn't guarantee complete absence of taint issues.

In conclusion, the plugin demonstrates commendable attention to fundamental security principles like prepared statements and output escaping. The lack of past vulnerabilities is reassuring. The primary concerns revolve around the potential for insecure handling of file operations and external requests, and more critically, the complete lack of capability checks, which could lead to privilege escalation or unauthorized actions. While the current data suggests a low risk, a more in-depth review of how file operations and HTTP requests are managed, and the implementation of proper capability checks, would further solidify its security.

Key Concerns

  • No capability checks implemented
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

PiWeb Alerts for Contact Form 7 in Telegram Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

PiWeb Alerts for Contact Form 7 in Telegram Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

PiWeb Alerts for Contact Form 7 in Telegram Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
200 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped200 total outputs
Attack Surface

PiWeb Alerts for Contact Form 7 in Telegram Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionpisol_custom_field_chatsadmin/CustomFields.php:57
actionadmin_menuadmin/Menu.php:22
filterwpcf7_editor_panelsadmin/Meta_Box.php:19
actionwpcf7_after_saveadmin/Meta_Box.php:20
actionadmin_initadmin/Option.php:32
actionadmin_initadmin/Option.php:33
actionwpcf7_mail_sentadmin/Telegram.php:37
actionadmin_noticespiwebsolution-alerts-contact-form-7-telegram.php:24
Maintenance & Trust

PiWeb Alerts for Contact Form 7 in Telegram Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version7.4
Downloads388

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

PiWeb Alerts for Contact Form 7 in Telegram Developer Profile

PI Web Solution

33 plugins · 93K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
235 days
View full developer profile
Detection Fingerprints

How We Detect PiWeb Alerts for Contact Form 7 in Telegram

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/piwebsolution-alerts-contact-form-7-telegram/assets/css/admin.css/wp-content/plugins/piwebsolution-alerts-contact-form-7-telegram/assets/css/frontend.css/wp-content/plugins/piwebsolution-alerts-contact-form-7-telegram/assets/js/admin.js/wp-content/plugins/piwebsolution-alerts-contact-form-7-telegram/assets/js/frontend.js
Script Paths
/wp-content/plugins/piwebsolution-alerts-contact-form-7-telegram/assets/js/admin.js/wp-content/plugins/piwebsolution-alerts-contact-form-7-telegram/assets/js/frontend.js
Version Parameters
piwebsolution-alerts-contact-form-7-telegram/assets/css/admin.css?ver=piwebsolution-alerts-contact-form-7-telegram/assets/css/frontend.css?ver=piwebsolution-alerts-contact-form-7-telegram/assets/js/admin.js?ver=piwebsolution-alerts-contact-form-7-telegram/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
piwebsolution-alerts-contact-form-7-telegram-settings
HTML Comments
This is a free versionWorkes in Pro version only
Data Attributes
data-field-typedata-pro-version
FAQ

Frequently Asked Questions about PiWeb Alerts for Contact Form 7 in Telegram