Form Redirection For Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/rdr-for-cf7

Redirect Contact Form 7 submissions to a thank you page or custom URL with optional delay. Simple, lightweight, and easy to configure.

20 active installs v1.0.3 PHP 7.2+ WP 5.5+ Updated Jul 5, 2026
cf7-redirectcontact-form-7contact-form-redirectredirect-after-submitthank-you-page
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Form Redirection For Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Form Redirection For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "rdr-for-cf7" v1.0.2 demonstrates a generally strong security posture based on the static analysis. The absence of dangerous functions, SQL injection vulnerabilities (100% prepared statements), file operations, and external HTTP requests are significant strengths. The plugin also incorporates proper nonce checks, which is a good practice for protecting against CSRF attacks. The high percentage of properly escaped output (83%) is also encouraging.

However, a notable concern is the complete lack of capability checks on its two AJAX entry points. While nonce checks are present, the absence of authorization checks means that any authenticated user, regardless of their role or permissions, could potentially trigger these AJAX actions. This significantly increases the attack surface for privilege escalation or unauthorized actions if the AJAX handlers perform sensitive operations. The plugin has no recorded vulnerability history, which is a positive sign, but it doesn't excuse the potential risks identified in the code.

In conclusion, while the plugin avoids common pitfalls like unescaped output and raw SQL, the lack of capability checks on its AJAX handlers represents a significant security gap. This weakness, combined with a moderate attack surface, warrants careful consideration. Future development should prioritize implementing capability checks to ensure that only authorized users can interact with these entry points, thereby improving its overall security robustness.

Key Concerns

  • Missing capability checks on AJAX handlers
  • Moderate attack surface without authorization
  • 83% of output escaped, leaving some potentially unescaped
Vulnerabilities
None known

Form Redirection For Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Form Redirection For Contact Form 7 Release Timeline

v1.0.3Current
v1.0.2
Code Analysis
Analyzed Mar 16, 2026

Form Redirection For Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
34 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped41 total outputs
Attack Surface

Form Redirection For Contact Form 7 Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_cf7rdr_get_redirectrdr-for-cf7.php:129
noprivwp_ajax_cf7rdr_get_redirectrdr-for-cf7.php:130
WordPress Hooks 6
actionplugins_loadedrdr-for-cf7.php:15
actionadmin_noticesrdr-for-cf7.php:18
actionwpcf7_editor_panelsrdr-for-cf7.php:26
actionadmin_enqueue_scriptsrdr-for-cf7.php:40
actionwpcf7_save_contact_formrdr-for-cf7.php:81
actionwp_footerrdr-for-cf7.php:97
Maintenance & Trust

Form Redirection For Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJul 5, 2026
PHP min version7.2
Downloads542

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Form Redirection For Contact Form 7 Developer Profile

Sachin Gadhavi

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Form Redirection For Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rdr-for-cf7/assets/admin-assets/style.css/wp-content/plugins/rdr-for-cf7/assets/admin-assets/script.js
Script Paths
/wp-content/plugins/rdr-for-cf7/assets/admin-assets/script.js
Version Parameters
rdr-for-cf7/assets/admin-assets/style.css?ver=rdr-for-cf7/assets/admin-assets/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
cf7rdr-toggle-wrappercf7rdr-toggle-switchcf7rdr-toggle-slidercf7rdr-redir-disabled
Data Attributes
id="cf7rdr_redirect_enabled"name="cf7rdr_redirect_enabled"id="cf7rdr_redirect_page"name="cf7rdr_redirect_page"id="cf7rdr_redirect_url"name="cf7rdr_redirect_url"+2 more
REST Endpoints
/wp-json/wpcf7/v1/contact-forms
FAQ

Frequently Asked Questions about Form Redirection For Contact Form 7