
Sitepact's Contact Form 7 Extension For Klaviyo Security & Risk Analysis
wordpress.org/plugins/sitepact-klaviyo-contact-form-7Integrate Contact Form 7 with Klaviyo. Automatically add form submissions to predetermined lists and fields in Klaviyo.
Is Sitepact's Contact Form 7 Extension For Klaviyo Safe to Use in 2026?
Generally Safe
Score 90/100Sitepact's Contact Form 7 Extension For Klaviyo has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The sitepact-klaviyo-contact-form-7 plugin v3.1.7 exhibits a mixed security posture. On the positive side, static analysis reveals excellent practices in handling SQL queries and output escaping, with 100% of both using prepared statements and proper escaping respectively. The absence of directly vulnerable AJAX handlers, REST API routes, shortcodes, and cron events, along with a clean taint analysis showing no unsanitized flows, suggests a well-developed codebase in these areas. The presence of nonce and capability checks further bolsters its security, indicating an awareness of common WordPress vulnerabilities.
However, a significant concern arises from the plugin's vulnerability history. It has a documented critical CVE for SQL injection, which, although currently patched, points to a past weakness in input validation or query construction. The existence of a critical vulnerability, even if resolved, warrants vigilance. Additionally, the plugin makes 6 external HTTP requests, which could be a potential vector for various attacks if not handled securely and if the remote endpoints are compromised.
In conclusion, while the current version of sitepact-klaviyo-contact-form-7 demonstrates strong internal security practices for SQL and output handling, its past critical vulnerability underscores the importance of continuous security monitoring and updates. The external HTTP requests also represent a potential, albeit less severe, area of concern that requires careful management.
Key Concerns
- Previous critical CVE for SQL Injection
- External HTTP requests made by plugin
Sitepact's Contact Form 7 Extension For Klaviyo Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Sitepact's Contact Form 7 Extension For Klaviyo <= 1.0.5 - Unauthenticated SQL Injection
Sitepact's Contact Form 7 Extension For Klaviyo Release Timeline
Sitepact's Contact Form 7 Extension For Klaviyo Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Sitepact's Contact Form 7 Extension For Klaviyo Attack Surface
AJAX Handlers 2
WordPress Hooks 14
Maintenance & Trust
Sitepact's Contact Form 7 Extension For Klaviyo Maintenance & Trust
Maintenance Signals
Community Trust
Sitepact's Contact Form 7 Extension For Klaviyo Alternatives
Mailster Contact Form 7
mailster-contact-form-7
Create your Signup Forms with Contact Form 7 and allow users to signup to your newsletter.
MailChimp Add-On for FormCraft
mailchimp-for-formcraft
Create gorgeous optin forms for your site with FormCraft, and grow your MailChimp list.
Connect Contact Form 7 and AWeber
integrate-contact-form-7-and-aweber
Integrate AWeber mailing lists with Contact Form 7. Automatically add form subscribers to your AWeber lists.
Smaily for Contact Form 7
smaily-for-contact-form-7
Flexible and straightforward Smaily newsletter integration for Contact Form 7.
Contact Form 7 – Campaign Monitor Addon
contact-form-7-campaignmonitor-addon
Add the capability to create newsletter opt-in forms with Contact Form 7. Automatically submit subscribers to predetermined lists in Campaign Monitor.
Sitepact's Contact Form 7 Extension For Klaviyo Developer Profile
2 plugins · 600 total installs
How We Detect Sitepact's Contact Form 7 Extension For Klaviyo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sitepact-klaviyo-contact-form-7/includes/assets/css/custom_bootstrap.css/wp-content/plugins/sitepact-klaviyo-contact-form-7/includes/assets/js/klcf-init.js/wp-content/plugins/sitepact-klaviyo-contact-form-7/includes/assets/js/klcf-init.jssitepact-klaviyo-contact-form-7/includes/assets/css/custom_bootstrap.css?ver=sitepact-klaviyo-contact-form-7/includes/assets/js/klcf-init.js?ver=HTML / DOM Fingerprints
klcf-nav-tabklcf-nav-tab-active<!-- Klaviyo Integration Settings -->data-klcf-nonceklcf_noncemain_klcf_script_ajax_object