SMS Alert for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/sms-alert-for-contact-form-7

SMS Alert for Contact Form 7 is a plugin for the popular contact form 7. So this is an extension for the CF7 plugin to send SMS alert.

10 active installs v1.0.0 PHP 5.2.4+ WP 4.5+ Updated May 7, 2019
cf7-smscontact-form-7-smssms-alertsms-alert-cf7sms-cf7
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is SMS Alert for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

SMS Alert for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "sms-alert-for-contact-form-7" plugin v1.0.0 demonstrates a generally good security posture based on the static analysis. It has a zero attack surface, meaning no AJAX handlers, REST API routes, shortcodes, or cron events were identified, which significantly reduces potential entry points for attackers. The code also shows a commitment to secure coding practices with 100% of SQL queries using prepared statements and no dangerous functions or file operations detected. The absence of any recorded vulnerabilities, historical or current, further bolsters its security image.

However, there are a few areas that warrant attention. The output escaping is only properly done for 22% of the outputs, which is a notable weakness. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered in the output without proper sanitization. Additionally, the plugin makes four external HTTP requests, which, while not inherently a vulnerability, can be a vector for related attacks like SSRF or if the target endpoints are compromised. The complete lack of nonce and capability checks, while seemingly mitigated by the zero attack surface, represents a missing layer of defense that could become relevant if new entry points are introduced in future versions.

Overall, the plugin is currently in a strong security position due to its minimal attack surface and clean vulnerability history. The primary concern lies in the insufficient output escaping, which needs to be addressed to prevent potential XSS issues. The absence of authentication and authorization checks, while not an immediate risk given the current structure, highlights a potential area for improvement in future development to ensure robustness against evolving threats.

Key Concerns

  • Low output escaping percentage
  • External HTTP requests
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

SMS Alert for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

SMS Alert for Contact Form 7 Release Timeline

v1.0
Code Analysis
Analyzed Mar 17, 2026

SMS Alert for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

22% escaped18 total outputs
Attack Surface

SMS Alert for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionwpcf7_before_send_mailsend_sms\msg91.php:2
actionwpcf7_before_send_mailsend_sms\nexmo.php:2
actionwpcf7_before_send_mailsend_sms\twilio.php:2
actionwpcf7_before_send_mailsend_sms\txtlcl.php:2
actionadmin_menusms_alert.php:18
actionadmin_initsms_alert.php:30
actionwpcf7_enqueue_stylessms_alert.php:99
actionwpcf7_enqueue_scriptssms_alert.php:106
Maintenance & Trust

SMS Alert for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedMay 7, 2019
PHP min version5.2.4
Downloads3K

Community Trust

Rating60/100
Number of ratings2
Active installs10
Developer Profile

SMS Alert for Contact Form 7 Developer Profile

informerfrk

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SMS Alert for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sms-alert-for-contact-form-7/assets/admin.js
Script Paths
/wp-content/plugins/sms-alert-for-contact-form-7/assets/admin.js

HTML / DOM Fingerprints

CSS Classes
cspd_imdb_option_form
Data Attributes
name="cspd_cf7_send_sms_using"name="cf7_admin_phone_number"name="cspd_cf7_sms_phone_field"name="cf7_enable_user_sms"name="cf7_enable_admin_sms"
JS Globals
cspd_cf7_sms_js
FAQ

Frequently Asked Questions about SMS Alert for Contact Form 7