
SendPress – Contact Form 7 Integration Security & Risk Analysis
wordpress.org/plugins/sendpress-contact-form-7SendPress is a free newsletter plugin for WordPress that makes it really simple to send out email newsletters to your subscription lists.
Is SendPress – Contact Form 7 Integration Safe to Use in 2026?
Generally Safe
Score 85/100SendPress – Contact Form 7 Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of SendPress Contact Form 7 v1.0 indicates a strong security posture in several key areas. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly positive. Furthermore, the high percentage of properly escaped output suggests good practices for preventing cross-site scripting (XSS) vulnerabilities.
However, a significant concern arises from the complete lack of nonces and capability checks across all entry points. While the current analysis reports zero entry points, this absence of fundamental security mechanisms is a critical weakness. If any entry points were to be introduced or discovered in future versions, they would likely be unprotected, creating a wide-open attack surface for various exploits. The vulnerability history being entirely clear is a positive sign, but it doesn't negate the inherent risks posed by missing authentication and authorization checks.
Key Concerns
- No nonce checks found
- No capability checks found
SendPress – Contact Form 7 Integration Security Vulnerabilities
SendPress – Contact Form 7 Integration Code Analysis
Output Escaping
SendPress – Contact Form 7 Integration Attack Surface
WordPress Hooks 6
Maintenance & Trust
SendPress – Contact Form 7 Integration Maintenance & Trust
Maintenance Signals
Community Trust
SendPress – Contact Form 7 Integration Alternatives
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Image CAPTCHA for Contact Form 7 and WPForms by HookAndHook (DSGVO/GDPR)
contact-form-7-image-captcha
Adds an Image CAPTCHA to Contact Form 7 and WPForms, GDPR ready, perfect WPForms or Contact Form 7 Spam Protection Image CAPTCHA, adds a honeypot
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
Ultra Addons for Contact Form 7
ultimate-addons-for-contact-form-7
50+ Essential Addons for Contact Form 7 - Conditional Fields, Multi Step, Redirection, Columns, WooCommerce, Mailchimp & more
GSheetConnector for CF7 – Connect Contact Form 7 to Google Sheets and Send Form Submissions in Real Time
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
SendPress – Contact Form 7 Integration Developer Profile
7 plugins · 1K total installs
How We Detect SendPress – Contact Form 7 Integration
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sendpress-contact-form-7/js/sendpress-signup.js/wp-content/plugins/sendpress-contact-form-7/css/sendpress-signup.css/wp-content/plugins/sendpress-contact-form-7/js/sendpress-signup.jssendpress-contact-form-7/js/sendpress-signup.js?ver=sendpress-contact-form-7/css/sendpress-signup.css?ver=HTML / DOM Fingerprints
wpcf7-form-control-wraparia-requirednamevaluecheckedidwpcf7_spnl_get_lists<input type="checkbox"