Popup Message Notifier for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/popup-notifier-for-contact-form-7

This plugin will show confirmation and error messages of CF7 inside a popup made with sweetalert2.

1K active installs v1.2.6 PHP 5.6+ WP 3.8.5+ Updated May 24, 2021
contact-form-7popup-confirmationpopup-messagepopup-sendresponse-message
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Popup Message Notifier for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

Popup Message Notifier for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin "popup-notifier-for-contact-form-7" v1.2.6 exhibits an excellent security posture based on the provided static analysis. There are no identified dangerous functions, file operations, external HTTP requests, or vulnerabilities in the SQL query handling, which all use prepared statements. Output escaping is consistently applied, and the absence of any taint analysis findings further reinforces its secure design. The plugin's vulnerability history is also clean, with no recorded CVEs, indicating a history of stable and secure development.

However, a notable concern arises from the complete lack of any identified entry points (AJAX handlers, REST API routes, shortcodes, cron events). While this suggests a minimal attack surface, it also raises questions about the plugin's actual functionality and how it integrates with WordPress. If the plugin is intended to interact with the WordPress environment, the absence of even basic checks like nonces or capability checks on potential entry points, if they exist but were not detected, could represent a significant oversight. This lack of detected security checks, combined with the zero attack surface, might indicate either a plugin that does very little, or one where potential entry points are hidden or not properly exposed for analysis.

In conclusion, the plugin demonstrates strong adherence to secure coding practices in its identified code paths. The absence of vulnerabilities and secure data handling are significant strengths. The primary area of potential concern stems from the complete lack of identified entry points and associated security checks. While this could mean a truly minimal plugin, it might also suggest an incomplete static analysis or a plugin with undocumented or poorly secured integration points. Further investigation into the plugin's intended functionality and integration methods would be advisable.

Key Concerns

  • No nonce checks detected
  • No capability checks detected
  • Zero detected entry points may mask issues
Vulnerabilities
None known

Popup Message Notifier for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Popup Message Notifier for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Popup Message Notifier for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_enqueue_scriptspopupnotifiercf7.php:85
actionadmin_enqueue_scriptspopupnotifiercf7.php:90
actionadmin_menupopupnotifiercf7.php:105
actionadmin_initpopupnotifiercf7.php:115
Maintenance & Trust

Popup Message Notifier for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 24, 2021
PHP min version5.6
Downloads6K

Community Trust

Rating100/100
Number of ratings5
Active installs1K
Developer Profile

Popup Message Notifier for Contact Form 7 Developer Profile

filippobenozzi

1 plugin · 1K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Popup Message Notifier for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/popup-notifier-for-contact-form-7/js/sweetalert.min.js/wp-content/plugins/popup-notifier-for-contact-form-7/js/popupnotifiercf7.js/wp-content/plugins/popup-notifier-for-contact-form-7/wp-color-picker-script.js
Script Paths
/wp-content/plugins/popup-notifier-for-contact-form-7/js/sweetalert.min.js/wp-content/plugins/popup-notifier-for-contact-form-7/js/popupnotifiercf7.js/wp-content/plugins/popup-notifier-for-contact-form-7/wp-color-picker-script.js
Version Parameters
popupnotifiercf7_custom_js?ver=1.0.0wp-color-picker-script-handle?ver=false

HTML / DOM Fingerprints

HTML Comments
<!-- Set default parameters on activation and after update --><!-- Remove parameters on deactivation --><!-- Enqueue scripts --><!-- Import parameters -->+2 more
JS Globals
PopUpParamsCF7
FAQ

Frequently Asked Questions about Popup Message Notifier for Contact Form 7