Save & Continue for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/save-continue-for-contact-form-7

Allow users to save Contact Form 7 progress and continue later. Reduce form abandonment with secure draft saving and resume functionality.

10 active installs v1.2.2 PHP 7.2+ WP 6.2+ Updated Feb 5, 2026
cf7contact-form-7continue-laterpersistent-formsave-form
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Save & Continue for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Save & Continue for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'save-continue-for-contact-form-7' plugin version 1.2.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, 100% utilization of prepared statements for SQL queries, and complete output escaping are excellent security practices. Furthermore, the presence of nonce checks on all AJAX handlers and capability checks on some entry points indicates a good understanding of WordPress security fundamentals. The plugin also has no recorded vulnerabilities, which is a positive indicator of its historical security.

However, the analysis reveals a potential concern regarding the attack surface. While all identified entry points (AJAX handlers, shortcodes, cron events) are reported as protected, a deeper review of the '0 without auth checks' for AJAX handlers is crucial. Even if capability checks are in place, the potential for privilege escalation or unintended actions exists if these checks are not robust enough. The lack of taint analysis results is not necessarily a negative, but it means potential vulnerabilities related to data flow and sanitization remain unevaluated.

In conclusion, the plugin demonstrates good adherence to secure coding practices, particularly in database interactions and output handling. The main area for caution lies in the thoroughness of authentication and authorization checks on its AJAX endpoints. The clean vulnerability history is encouraging, but ongoing vigilance and code review are always recommended for any plugin.

Vulnerabilities
None known

Save & Continue for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Save & Continue for Contact Form 7 Release Timeline

v1.2.2Current
v1.2.1
v1.2.0
v1.1.0
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Save & Continue for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
0
52 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

100% escaped52 total outputs
Attack Surface

Save & Continue for Contact Form 7 Attack Surface

Entry Points6
Unprotected0

AJAX Handlers 4

authwp_ajax_dwlscf_load_draftsrc/Frontend/ScriptLoader.php:26
noprivwp_ajax_dwlscf_load_draftsrc/Frontend/ScriptLoader.php:27
authwp_ajax_dwlscf_save_draftsrc/Service/SaveHandler.php:18
noprivwp_ajax_dwlscf_save_draftsrc/Service/SaveHandler.php:19

Shortcodes 2

[dwlscf-save-button] src/Shortcode/SaveShortcodes.php:17
[dwlscf-save-link-email] src/Shortcode/SaveShortcodes.php:18
WordPress Hooks 8
actionplugins_loadedsave-continue-for-contact-form-7.php:35
actionadmin_menusrc/Admin/SettingsPage.php:13
actionadmin_initsrc/Admin/SettingsPage.php:14
filterwpcf7_form_elementssrc/Frontend/ScriptLoader.php:22
actionwpcf7_enqueue_scriptssrc/Frontend/ScriptLoader.php:23
actionwpcf7_enqueue_stylessrc/Frontend/ScriptLoader.php:24
actionwp_footersrc/Frontend/ScriptLoader.php:25
actiondwlscf_cleanup_expired_draftssrc/Hooks/DraftCleanup.php:13

Scheduled Events 1

dwlscf_cleanup_expired_drafts
Maintenance & Trust

Save & Continue for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedFeb 5, 2026
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Save & Continue for Contact Form 7 Developer Profile

Maidul

12 plugins · 1K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
126 days
View full developer profile
Detection Fingerprints

How We Detect Save & Continue for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/save-continue-for-contact-form-7/assets/js/save-handler.js/wp-content/plugins/save-continue-for-contact-form-7/assets/js/load-handler.js/wp-content/plugins/save-continue-for-contact-form-7/assets/css/save-style.css
Script Paths
assets/js/save-handler.jsassets/js/load-handler.js
Version Parameters
save-continue-for-contact-form-7/assets/js/save-handler.js?ver=save-continue-for-contact-form-7/assets/js/load-handler.js?ver=save-continue-for-contact-form-7/assets/css/save-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
dwlscf-save-draftdwlscf-color-red
Data Attributes
data-dwlscf-token
JS Globals
dwlscfSaveContinue
REST Endpoints
/wp-json/dwlscf/v1/save-draft/wp-json/dwlscf/v1/load-draft
Shortcode Output
[dwlscf-save-button][dwlscf-save-link-email]
FAQ

Frequently Asked Questions about Save & Continue for Contact Form 7