Simple Redirection for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/simple-redirection-for-contact-form-7

Simple redirection addon for Contact Form 7, allows you to redirect to an existing page or a custom URL after form submission.

70 active installs v1.0.2 PHP 5.6+ WP 3.0.1+ Updated Mar 4, 2021
cf7-redirectcontact-form-7-redirectionredirect-formredirectionsimple-redirection
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Simple Redirection for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

Simple Redirection for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

Based on the provided static analysis, the "simple-redirection-for-contact-form-7" plugin v1.0.2 exhibits a strong security posture. The absence of any identified dangerous functions, SQL queries without prepared statements, file operations, or external HTTP requests is commendable. Furthermore, the plugin has no recorded vulnerabilities, indicating a history of stable and secure development. The attack surface appears minimal, with no apparent entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without authentication checks.

While the lack of taint analysis flows and critical/high severity issues is a positive sign, the incomplete output escaping (63% properly escaped) presents a minor concern. Although not a direct critical risk based on this data, it suggests potential for cross-site scripting (XSS) vulnerabilities if the unescaped outputs are user-controlled. The absence of nonce and capability checks, coupled with a zero-length attack surface, could be interpreted in two ways: either there are no user-interactive features that would require these checks, or the plugin is inherently insecure by design, relying solely on the absence of direct entry points for its security. Given the limited data, it's difficult to definitively assess the latter.

In conclusion, the plugin demonstrates good practices in several key security areas, particularly in its handling of database queries and the absence of known vulnerabilities. The primary area for potential improvement lies in ensuring complete output escaping. The minimal attack surface is a strength, but the lack of specific checks warrants a cautious approach, assuming the plugin's functionality does not necessitate them.

Key Concerns

  • Output escaping not fully implemented
Vulnerabilities
None known

Simple Redirection for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Simple Redirection for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

63% escaped8 total outputs
Attack Surface

Simple Redirection for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedincludes\class-dck-cf7-simple-redirection.php:38
actionadmin_enqueue_scriptsincludes\class-dck-cf7-simple-redirection.php:44
actionadmin_enqueue_scriptsincludes\class-dck-cf7-simple-redirection.php:45
filterwpcf7_editor_panelsincludes\class-dck-cf7-simple-redirection.php:48
filterwpcf7_after_updateincludes\class-dck-cf7-simple-redirection.php:49
actionwpcf7_after_saveincludes\class-dck-cf7-simple-redirection.php:52
filterwpcf7_feedback_responseincludes\class-dck-cf7-simple-redirection.php:53
actionwp_enqueue_scriptsincludes\class-dck-cf7-simple-redirection.php:70
Maintenance & Trust

Simple Redirection for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMar 4, 2021
PHP min version5.6
Downloads8K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Developer Profile

Simple Redirection for Contact Form 7 Developer Profile

Darpan Kulkarni

2 plugins · 80 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Simple Redirection for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-redirection-for-contact-form-7/admin/js/dck-cf7-simple-redirection-admin.min.js/wp-content/plugins/simple-redirection-for-contact-form-7/admin/css/dck-cf7-simple-redirection-admin.min.css/wp-content/plugins/simple-redirection-for-contact-form-7/public/js/dck-cf7-simple-redirection-public.min.js
Script Paths
plugin_dir_url(__FILE__) . 'js/dck-cf7-simple-redirection-admin.min.js'plugin_dir_url(__FILE__) . 'js/dck-cf7-simple-redirection-public.min.js'
Version Parameters
dck-cf7-simple-redirection-admin.min.css?ver=dck-cf7-simple-redirection-admin.min.js?ver=dck-cf7-simple-redirection-public.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
dck-cf7-sr-panel
Data Attributes
id="dck_cf7_sr_enabled"id="dck_cf7_sr_type"id="dck_cf7_sr_page_id"id="dck_cf7_sr_custom_url"id="dck_cf7_sr_new_tab"id="dck_cf7_sr_delay"
Shortcode Output
__('Simple Redirection', 'dck-cf7-simple-redirection')__('Enable redirect:', 'dck-cf7-simple-redirection')__('Redirect type:', 'dck-cf7-simple-redirection')
FAQ

Frequently Asked Questions about Simple Redirection for Contact Form 7