Product Dropdown Selector for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/product-dropdown-selector-for-contact-form-7

Enhanced WooCommerce product dropdown field for Contact Form 7 with advanced filters, Select2 support, and customizable product selection.

20 active installs v1.3 PHP 7.0+ WP 5.0+ Updated Jul 13, 2025
contact-form-7form-selectorproduct-dropdownproduct-filterwoocommerce-dropdown
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Product Dropdown Selector for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Product Dropdown Selector for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "product-dropdown-selector-for-contact-form-7" plugin, version 1.3, exhibits a strong security posture based on the provided static analysis. The complete absence of identified dangerous functions, SQL queries executed without prepared statements, and the extremely high percentage of properly escaped output are significant strengths. Furthermore, the lack of file operations, external HTTP requests, and a zero attack surface through common entry points like AJAX handlers, REST API routes, shortcodes, and cron events suggest a well-contained and defensively coded plugin. The vulnerability history also shows no recorded CVEs, indicating a good track record. However, the lack of nonce checks and capability checks, particularly given the potential for this plugin to interact with Contact Form 7's functionalities, represents a potential area for concern, even though no direct vulnerabilities were found in these areas during this specific static analysis. This is compounded by the use of a bundled library, Select2, which, if outdated, could introduce vulnerabilities not directly evident in the plugin's own code. While the current analysis is very positive, ongoing vigilance regarding potential supply chain attacks or future zero-day vulnerabilities within bundled libraries or newly discovered attack vectors is advised.

Key Concerns

  • Missing nonce checks on entry points
  • Bundled Select2 library may be outdated
  • No capability checks on entry points
Vulnerabilities
None known

Product Dropdown Selector for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Product Dropdown Selector for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
120 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

98% escaped122 total outputs
Attack Surface

Product Dropdown Selector for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwpcf7_admin_initincludes\class-product-dropdown-admin.php:12
actionadmin_enqueue_scriptsincludes\class-product-dropdown-admin.php:15
actionwpcf7_initincludes\class-product-dropdown-frontend.php:17
actionwp_enqueue_scriptsincludes\class-product-dropdown-frontend.php:20
actionplugins_loadedproduct-dropdown-selector-cf7.php:48
Maintenance & Trust

Product Dropdown Selector for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 13, 2025
PHP min version7.0
Downloads768

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Product Dropdown Selector for Contact Form 7 Developer Profile

Pluginorbit

2 plugins · 30 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Product Dropdown Selector for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/product-dropdown-selector-for-contact-form-7/assets/js/pdscf7-admin-script.js/wp-content/plugins/product-dropdown-selector-for-contact-form-7/assets/css/pdscf7-admin-style.css
Generator Patterns
product-dropdownProduct Dropdown
Script Paths
/wp-content/plugins/product-dropdown-selector-for-contact-form-7/assets/js/pdscf7-admin-script.js
Version Parameters
product-dropdown-selector-for-contact-form-7/assets/js/pdscf7-admin-script.js?ver=product-dropdown-selector-for-contact-form-7/assets/css/pdscf7-admin-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
pdscf7_productoptionslist_categorylist_taglist_colorlist_sizelist_pricelist_stock_statuslist_product_id+2 more
Data Attributes
id="pdscf7_productoptions"class="product-name oneline"class="product-id oneline option"class="product-class oneline option"
JS Globals
PDSCF7_PLUGIN_URL
Shortcode Output
<select name="pdscf7_productoptions" id="pdscf7_productoptions">
FAQ

Frequently Asked Questions about Product Dropdown Selector for Contact Form 7