
SMS Alert for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/sms-alert-for-contact-form-7SMS Alert for Contact Form 7 is a plugin for the popular contact form 7. So this is an extension for the CF7 plugin to send SMS alert.
Is SMS Alert for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100SMS Alert for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sms-alert-for-contact-form-7" plugin v1.0.0 demonstrates a generally good security posture based on the static analysis. It has a zero attack surface, meaning no AJAX handlers, REST API routes, shortcodes, or cron events were identified, which significantly reduces potential entry points for attackers. The code also shows a commitment to secure coding practices with 100% of SQL queries using prepared statements and no dangerous functions or file operations detected. The absence of any recorded vulnerabilities, historical or current, further bolsters its security image.
However, there are a few areas that warrant attention. The output escaping is only properly done for 22% of the outputs, which is a notable weakness. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered in the output without proper sanitization. Additionally, the plugin makes four external HTTP requests, which, while not inherently a vulnerability, can be a vector for related attacks like SSRF or if the target endpoints are compromised. The complete lack of nonce and capability checks, while seemingly mitigated by the zero attack surface, represents a missing layer of defense that could become relevant if new entry points are introduced in future versions.
Overall, the plugin is currently in a strong security position due to its minimal attack surface and clean vulnerability history. The primary concern lies in the insufficient output escaping, which needs to be addressed to prevent potential XSS issues. The absence of authentication and authorization checks, while not an immediate risk given the current structure, highlights a potential area for improvement in future development to ensure robustness against evolving threats.
Key Concerns
- Low output escaping percentage
- External HTTP requests
- Missing nonce checks
- Missing capability checks
SMS Alert for Contact Form 7 Security Vulnerabilities
SMS Alert for Contact Form 7 Release Timeline
SMS Alert for Contact Form 7 Code Analysis
Output Escaping
SMS Alert for Contact Form 7 Attack Surface
WordPress Hooks 8
Maintenance & Trust
SMS Alert for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
SMS Alert for Contact Form 7 Alternatives
PeproDev CF7 SMS Notifier
pepro-cf7-sms-notifier
Send notifications to User and Admins upon Contact Form 7 Submission
CRSMS Contact Form 7 SMS Notification
crsms-contact-form-7-sms-notification
Works with the Contact Form 7 plugin to send SMS notifications when somebody submits your contact form, using the API Configured By Site Admin
SMS Confirmation for WooCommerce
sms-confirmation-for-woocommerce
Send SMS notifications when WooCommerce orders are completed using SMS.net.bd, ensuring real-time updates and better customer engagement.
ZycoonApps Login SMS Alert
zycoonapps-login-sms-alert
Want an alert on successful Admin Login? ZycoonApps Login SMS Alert can alert you via SMS of the login incident including the IP address.
SMS Alert for Contact Form 7 Developer Profile
1 plugin · 10 total installs
How We Detect SMS Alert for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sms-alert-for-contact-form-7/assets/admin.js/wp-content/plugins/sms-alert-for-contact-form-7/assets/admin.jsHTML / DOM Fingerprints
cspd_imdb_option_formname="cspd_cf7_send_sms_using"name="cf7_admin_phone_number"name="cspd_cf7_sms_phone_field"name="cf7_enable_user_sms"name="cf7_enable_admin_sms"cspd_cf7_sms_js