Source Medium Tracker for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/source-medium-tracker-for-contact-form-7

Tracks the source and medium of visitors and includes this information in Contact Form 7 submissions.

100 active installs v2.5 PHP 7.0+ WP 5.0+ Updated Aug 20, 2025
contact-form-7mediumsourcetrackingutm
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Source Medium Tracker for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Source Medium Tracker for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "source-medium-tracker-for-contact-form-7" plugin version 2.5 exhibits a generally strong security posture based on the provided static analysis. The plugin effectively utilizes prepared statements for all its SQL queries, demonstrates robust output escaping with 92% of outputs properly handled, and implements nonce checks and capability checks where appropriate. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure design. Crucially, the taint analysis found no critical or high severity flows with unsanitized paths, indicating no immediate risks of code injection or data manipulation through untrusted input. The plugin also has no recorded vulnerability history, which is a positive indicator of its ongoing security maintenance.

While the static analysis reveals excellent adherence to secure coding practices, the limited attack surface (one AJAX handler, zero REST API routes, shortcodes, or cron events) makes it difficult to draw sweeping conclusions about its overall security in all potential scenarios. However, the single AJAX handler appears to be protected by the identified nonce and capability checks, mitigating common web application vulnerabilities. The plugin's strengths lie in its careful handling of database operations and output, and the absence of historical vulnerabilities. The primary weakness, if any, would be the limited scope of the analysis provided, rather than any inherent flaws identified in the code itself.

Vulnerabilities
None known

Source Medium Tracker for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Source Medium Tracker for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
12 prepared
Unescaped Output
7
80 escaped
Nonce Checks
3
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared12 total queries

Output Escaping

92% escaped87 total outputs
Data Flows
All sanitized

Data Flow Analysis

4 flows
smt_cf7_render_admin_page (includes\admin-page.php:107)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Source Medium Tracker for Contact Form 7 Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_smt_cf7_get_submission_datasource-medium-tracker-for-contact-form-7.php:277
WordPress Hooks 15
actionadmin_enqueue_scriptsincludes\admin-page.php:6
actionadmin_initincludes\class-smt-cf7-admin.php:15
actionadmin_menuincludes\class-smt-cf7-admin.php:18
actionwp_headincludes\class-smt-cf7-public.php:7
actionwp_headincludes\class-smt-cf7-public.php:8
actionwp_enqueue_scriptsincludes\class-smt-cf7-public.php:11
actionplugins_loadedsource-medium-tracker-for-contact-form-7.php:51
actionadmin_noticessource-medium-tracker-for-contact-form-7.php:56
actionwp_enqueue_scriptssource-medium-tracker-for-contact-form-7.php:67
filterwpcf7_form_elementssource-medium-tracker-for-contact-form-7.php:70
actionwpcf7_mail_sentsource-medium-tracker-for-contact-form-7.php:73
filterwpcf7_form_elementssource-medium-tracker-for-contact-form-7.php:101
actionwpcf7_before_send_mailsource-medium-tracker-for-contact-form-7.php:109
actionwpcf7_mail_sentsource-medium-tracker-for-contact-form-7.php:130
actionwp_dashboard_setupsource-medium-tracker-for-contact-form-7.php:140
Maintenance & Trust

Source Medium Tracker for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 20, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Source Medium Tracker for Contact Form 7 Developer Profile

asynadak

2 plugins · 100 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Source Medium Tracker for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/source-medium-tracker-for-contact-form-7/js/smt-cf7-tracking.js
Version Parameters
source-medium-tracker-for-contact-form-7/js/smt-cf7-tracking.js?ver=

HTML / DOM Fingerprints

CSS Classes
smt-cf7-kpissmt-cf7-kpismt-cf7-comparesmt-cf7-compare-iconsmt-cf7-compare-text
Data Attributes
name="source"name="medium"
Shortcode Output
<input type="hidden" name="source" value="Unknown" /><input type="hidden" name="medium" value="Unknown" />
FAQ

Frequently Asked Questions about Source Medium Tracker for Contact Form 7