Send Everything for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/send-everything-cf7

WordPress plugin. Extension for Contact Form 7. Adds a mail-tag [everything] that sends all fields in the message body.

100 active installs v1.2.1 PHP + WP + Updated Dec 18, 2024
contact-formcontact-form-7email
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Send Everything for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 92/100

Send Everything for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of "send-everything-cf7" v1.2.1 reveals a strong security posture. The plugin demonstrates excellent adherence to secure coding practices, with no identified dangerous functions, no direct SQL queries (all use prepared statements), and complete output escaping. Furthermore, there are no file operations or external HTTP requests, and the absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. The presence of capability checks indicates a conscious effort to restrict access to certain functionalities. The taint analysis also shows no identified vulnerabilities, reinforcing the positive findings from the code signals. The plugin's vulnerability history is clean, with zero known CVEs, further enhancing its security profile. This indicates a well-developed and maintained plugin that prioritizes security. The overall security is very good.

Vulnerabilities
None known

Send Everything for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Send Everything for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

Send Everything for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actioninitsend-everything-cf7.php:42
actionwpcf7_config_validator_validatesend-everything-cf7.php:45
filterwpcf7_config_validator_available_error_codessend-everything-cf7.php:48
filterwpcf7_mail_componentssend-everything-cf7.php:51
filterwpcf7_collect_mail_tagssend-everything-cf7.php:54
filterwpcf7_contact_form_propertiessend-everything-cf7.php:57
filterwpcf7_contact_form_default_packsend-everything-cf7.php:63
filterwp_mail_content_typesend-everything-cf7.php:263
Maintenance & Trust

Send Everything for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedDec 18, 2024
PHP min version
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Send Everything for Contact Form 7 Developer Profile

Corey Salzano

11 plugins · 7K total installs

94
trust score
Avg Security Score
91/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Send Everything for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
[everything]
FAQ

Frequently Asked Questions about Send Everything for Contact Form 7