
ShopMagic for Contact Form 7 and WooCommerce Security & Risk Analysis
wordpress.org/plugins/shopmagic-for-contact-form-7Allows creating WooCommerce marketing automation and emailing WordPress users based on Contact Form 7 submission. You can use this Contact Form 7 inte …
Is ShopMagic for Contact Form 7 and WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100ShopMagic for Contact Form 7 and WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shopmagic-for-contact-form-7" plugin version 1.3.18 exhibits a generally strong security posture based on the provided static analysis. It has no recorded vulnerabilities (CVEs) and demonstrates good security practices such as implementing nonce and capability checks for its single AJAX entry point, suggesting that direct access to its functionality is likely protected. The absence of unescaped output in critical areas and the lack of exploitable taint flows further contribute to its good security standing. However, the plugin's reliance on raw SQL queries without prepared statements is a significant concern. While the analysis shows only two such queries and no immediate critical taint flows, this practice can expose the application to SQL injection vulnerabilities if the input is not meticulously sanitized elsewhere, which is not guaranteed by this analysis alone. The limited attack surface and absence of external HTTP requests are positive indicators, but the SQL query handling remains a notable weakness.
Key Concerns
- SQL queries without prepared statements
ShopMagic for Contact Form 7 and WooCommerce Security Vulnerabilities
ShopMagic for Contact Form 7 and WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
ShopMagic for Contact Form 7 and WooCommerce Attack Surface
AJAX Handlers 1
WordPress Hooks 21
Maintenance & Trust
ShopMagic for Contact Form 7 and WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
ShopMagic for Contact Form 7 and WooCommerce Alternatives
AroksDS Submission Alerts for Contact Form 7 to Telegram
aroksds-alerts-for-cf7-to-telegram
Stop losing leads: send Contact Form 7 submissions to a shared Telegram channel as a reliable backup to email.
BCodeCraft Submissions for Contact Form 7
bcodecraft-submissions-cf7
Secure storage and management of Contact Form 7 submissions with advanced security features. Never lose a lead again!
CUB Form Database Manager
cub-cf7db
CUB - CF7DB: Save Contact Form 7 data to WordPress database. Manage, search, and export form entries easily in WP admin.
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
ShopMagic for Contact Form 7 and WooCommerce Developer Profile
23 plugins · 127K total installs
How We Detect ShopMagic for Contact Form 7 and WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shopmagic-for-contact-form-7/assets/css/admin-style.css/wp-content/plugins/shopmagic-for-contact-form-7/assets/js/scripts.js/wp-content/plugins/shopmagic-for-contact-form-7/assets/js/scripts.jsshopmagic-for-contact-form-7/assets/css/admin-style.css?ver=shopmagic-for-contact-form-7/assets/js/scripts.js?ver=HTML / DOM Fingerprints
shopmagic-cf7-admin-logoshopmagic-cf7-setup-wizard-button<!-- A widget to display shopmagic cf7 setup wizard button --><!-- wp_footer called, do not do anything here -->data-cf7-shopmagic-ajax-urlShopMagicCF7