Referrer Input for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/referrer-input-for-contact-form-7

Contact Form 7 Addon that creates a cache-resistant input that contains the URL of the page the user visited before the contact form page.

500 active installs v1.0.1 PHP + WP 1.4.0+ Updated Jan 11, 2017
contact-form-7cssjavascriptjqueryreferrer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Referrer Input for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

Referrer Input for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

Based on the static analysis, the "referrer-input-for-contact-form-7" plugin version 1.0.1 presents a generally strong security posture. The absence of any identified dangerous functions, SQL injection risks, file operations, or external HTTP requests is highly positive. Furthermore, the code demonstrates good practices with 100% of SQL queries using prepared statements and a very high rate of properly escaped output. The presence of at least one capability check also indicates an awareness of access control. The plugin's attack surface is reported as zero, which is an excellent sign regarding entry points.

The taint analysis shows no identified flows, further reinforcing the impression of secure coding. The vulnerability history being completely clean with no recorded CVEs, regardless of severity, strongly suggests a well-maintained and secure codebase over time. The plugin's adherence to secure coding principles and lack of historical security incidents make it appear to be a low-risk component.

In conclusion, this plugin demonstrates a commendable focus on security. The reported metrics are overwhelmingly positive, indicating robust security practices and a lack of exploitable vulnerabilities in the analyzed version. While no code is perfectly secure, the data provided paints a picture of a highly trustworthy plugin.

Key Concerns

  • No identified critical or high severity issues
  • No taint flows with unsanitized paths
  • 100% SQL queries using prepared statements
  • 96% properly escaped output
  • No dangerous functions
  • No file operations
  • No external HTTP requests
  • Zero attack surface
  • No known CVEs
Vulnerabilities
None known

Referrer Input for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Referrer Input for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
22 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

96% escaped23 total outputs
Attack Surface

Referrer Input for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_initactivation-checks.php:3
actionadmin_noticesactivation-checks.php:6
actionwpcf7_initform-tag.php:3
actionwpcf7_admin_inittag.php:3
Maintenance & Trust

Referrer Input for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedJan 11, 2017
PHP min version
Downloads4K

Community Trust

Rating84/100
Number of ratings5
Active installs500
Developer Profile

Referrer Input for Contact Form 7 Developer Profile

damiarita

3 plugins · 630 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Referrer Input for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/referrer-input-for-contact-form-7/script.js/wp-content/plugins/referrer-input-for-contact-form-7/script.min.js
Script Paths
/wp-content/plugins/referrer-input-for-contact-form-7/script.js/wp-content/plugins/referrer-input-for-contact-form-7/script.min.js
Version Parameters
referrer-input-for-contact-form-7/script.js?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
cf7-rfr
Data Attributes
cf7rfr_referrer
Shortcode Output
<input type="hidden" name="
FAQ

Frequently Asked Questions about Referrer Input for Contact Form 7