SendPress – Contact Form 7 Integration Security & Risk Analysis

wordpress.org/plugins/sendpress-contact-form-7

SendPress is a free newsletter plugin for WordPress that makes it really simple to send out email newsletters to your subscription lists.

30 active installs v1.0 PHP + WP 3.7.1+ Updated May 25, 2016
contact-formcontact-form-7formformssendpress
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SendPress – Contact Form 7 Integration Safe to Use in 2026?

Generally Safe

Score 85/100

SendPress – Contact Form 7 Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The static analysis of SendPress Contact Form 7 v1.0 indicates a strong security posture in several key areas. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is highly positive. Furthermore, the high percentage of properly escaped output suggests good practices for preventing cross-site scripting (XSS) vulnerabilities.

However, a significant concern arises from the complete lack of nonces and capability checks across all entry points. While the current analysis reports zero entry points, this absence of fundamental security mechanisms is a critical weakness. If any entry points were to be introduced or discovered in future versions, they would likely be unprotected, creating a wide-open attack surface for various exploits. The vulnerability history being entirely clear is a positive sign, but it doesn't negate the inherent risks posed by missing authentication and authorization checks.

Key Concerns

  • No nonce checks found
  • No capability checks found
Vulnerabilities
None known

SendPress – Contact Form 7 Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

SendPress – Contact Form 7 Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
54 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped57 total outputs
Attack Surface

SendPress – Contact Form 7 Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninitmodules\sendpress-signup.php:7
filterwpcf7_validate_spnlmodules\sendpress-signup.php:131
filterwpcf7_validate_spnl*modules\sendpress-signup.php:132
actionadmin_initmodules\sendpress-signup.php:168
actionwpcf7_before_send_mailmodules\sendpress-signup.php:269
filterwpcf7_mail_tag_replacedmodules\sendpress-signup.php:401
Maintenance & Trust

SendPress – Contact Form 7 Integration Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedMay 25, 2016
PHP min version
Downloads6K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

SendPress – Contact Form 7 Integration Developer Profile

Josh Lyford

7 plugins · 1K total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SendPress – Contact Form 7 Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sendpress-contact-form-7/js/sendpress-signup.js/wp-content/plugins/sendpress-contact-form-7/css/sendpress-signup.css
Script Paths
/wp-content/plugins/sendpress-contact-form-7/js/sendpress-signup.js
Version Parameters
sendpress-contact-form-7/js/sendpress-signup.js?ver=sendpress-contact-form-7/css/sendpress-signup.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpcf7-form-control-wrap
Data Attributes
aria-requirednamevaluecheckedid
JS Globals
wpcf7_spnl_get_lists
Shortcode Output
<input type="checkbox"
FAQ

Frequently Asked Questions about SendPress – Contact Form 7 Integration