
Power Form 7: Power Automate Connector for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/power-form-7Integrate Contact Form 7 with Microsoft Power Automate. Trigger flows and/or submit data to any Contact Form 7 form.
Is Power Form 7: Power Automate Connector for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 92/100Power Form 7: Power Automate Connector for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "power-form-7" v2.6.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events with unprotected entry points is a significant positive. Furthermore, the plugin exclusively uses prepared statements for all its SQL queries, mitigating the risk of SQL injection vulnerabilities. The presence of capability checks for its file operations and external HTTP requests indicates a deliberate effort to secure these functionalities.
However, there are areas for improvement. The 50% rate of properly escaped output is a concern, as it leaves potential for cross-site scripting (XSS) vulnerabilities if sensitive data is not handled with care. The lack of nonce checks, while not directly tied to an attack surface in this specific analysis, is a missed opportunity for robust protection against CSRF attacks, especially if new entry points are introduced in the future. The plugin's vulnerability history is remarkably clean, with no recorded CVEs, which suggests a history of secure development or perhaps limited exposure. Overall, the plugin demonstrates good foundational security practices, particularly in data handling and query execution, but lacks comprehensive output sanitization and cross-site request forgery protection.
Key Concerns
- 50% of outputs are not properly escaped
- 0 Nonce checks found
Power Form 7: Power Automate Connector for Contact Form 7 Security Vulnerabilities
Power Form 7: Power Automate Connector for Contact Form 7 Release Timeline
Power Form 7: Power Automate Connector for Contact Form 7 Code Analysis
Output Escaping
Data Flow Analysis
Power Form 7: Power Automate Connector for Contact Form 7 Attack Surface
WordPress Hooks 15
Maintenance & Trust
Power Form 7: Power Automate Connector for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Power Form 7: Power Automate Connector for Contact Form 7 Alternatives
GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
CleverReach Integration for Contact Form 7
cf7-cleverreach-integration
Connect your Contact Form 7 forms with your CleverReach account.
Integration of Bitrix24 with Contact Form 7
cf7-bitrix24-integration
Плагин для интеграции Битрикс24 с контактной формой 7.
Integration of Zoho CRM and Contact Form 7
integration-of-zoho-crm-and-contact-form-7
Visit plugin's website
GB To Powerlink
gb-powerlink-lite
GB To Powerlink allows Fireberry CRM (formerly known as PowerLink) users to easily integrate Contact Form 7 with their Fireberry CRM.
Power Form 7: Power Automate Connector for Contact Form 7 Developer Profile
2 plugins · 200 total installs
How We Detect Power Form 7: Power Automate Connector for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/power-form-7/css/pf7-admin-style.css/wp-content/plugins/power-form-7/js/pf7-admin-script.js/wp-content/plugins/power-form-7/css/pf7-public-style.css/wp-content/plugins/power-form-7/js/pf7-public-script.js/wp-content/plugins/power-form-7/js/pf7-admin-script.js/wp-content/plugins/power-form-7/js/pf7-public-script.jspower-form-7/css/pf7-admin-style.css?ver=power-form-7/js/pf7-admin-script.js?ver=power-form-7/css/pf7-public-style.css?ver=power-form-7/js/pf7-public-script.js?ver=HTML / DOM Fingerprints
pf7-admin-settings-wrap<!-- Options: { "license_key": "", "flow_user": "", "enabled": true } -->name="wpcf7-pf7[enabled]"name="wpcf7-pf7[license_key]"name="wpcf7-pf7[flow_user]"