
Send Data to AC Security & Risk Analysis
wordpress.org/plugins/send-cf7-data-to-active-campaignContact form 7 Addon plugin. send data to activate campaign list.
Is Send Data to AC Safe to Use in 2026?
Generally Safe
Score 85/100Send Data to AC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "send-cf7-data-to-active-campaign" v1.0 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for SQL, and 100% proper output escaping are excellent security practices. The presence of a nonce check is also a positive sign. Furthermore, the lack of any recorded vulnerabilities, including critical or high severity ones, suggests a history of secure development or diligent patching.
Despite these strengths, there is a notable absence of capability checks. While the plugin only has one AJAX handler and no REST API routes, shortcodes, or cron events, meaning a limited attack surface, relying solely on nonce checks for AJAX handlers can be a weakness. If the nonce check were to be bypassed or if an attacker could trigger the AJAX handler without a valid nonce, it could still lead to unauthorized actions if the handler itself doesn't perform further authorization checks. The lack of any critical or high severity issues in taint analysis is reassuring, but a complete absence of taint flows analyzed might also indicate a very limited scope of analysis or an extremely simple plugin.
In conclusion, this plugin appears to be developed with security in mind, particularly concerning data handling and output sanitization. However, the absence of capability checks on its sole AJAX entry point represents a potential, albeit small, security concern that could be addressed to further harden its defenses.
Key Concerns
- Missing capability checks on AJAX handler
Send Data to AC Security Vulnerabilities
Send Data to AC Release Timeline
Send Data to AC Code Analysis
Output Escaping
Send Data to AC Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Send Data to AC Maintenance & Trust
Maintenance Signals
Community Trust
Send Data to AC Alternatives
Active Campaign & Contact Form 7
wpop-accf
Add Contact Form 7 Data to ActiveCampaign Contact lists.
Contact Form 7
contact-form-7
Just another contact form plugin. Simple but flexible.
Akismet Anti-spam: Spam Protection
akismet
The best anti-spam protection to block spam comments and spam in a contact form. The most trusted antispam solution for WordPress and WooCommerce.
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
Send Data to AC Developer Profile
4 plugins · 20 total installs
How We Detect Send Data to AC
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/send-cf7-data-to-active-campaign/admin/js/admin-script.js/wp-content/plugins/send-cf7-data-to-active-campaign/admin/js/admin-script.jsHTML / DOM Fingerprints
active_campaign_urlactive_campaign_keyactive_campaign_tagactive_campaign_list_idsdac_ajax_objsdac_script