Spam Prevention for Contact Form 7 and Comments Security & Risk Analysis

wordpress.org/plugins/spam-prevention-for-contact-form-7-and-comments

Spam Prevention for WP Contact Form 7 (manage multiple contact forms) and WordPress Comments.

10 active installs v1.3.24 PHP + WP 4.7+ Updated Dec 23, 2025
commentscontact-form-7preventprotectionspam
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Spam Prevention for Contact Form 7 and Comments Safe to Use in 2026?

Generally Safe

Score 100/100

Spam Prevention for Contact Form 7 and Comments has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The security posture of the "spam-prevention-for-contact-form-7-and-comments" plugin, version 1.3.24, appears to be strong based on the provided static analysis and vulnerability history. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the potential attack surface. Furthermore, the code signals indicate good development practices, with no dangerous functions, all SQL queries using prepared statements, and a high percentage of output correctly escaped. The lack of file operations and external HTTP requests also reduces risk.

The taint analysis shows no flows with unsanitized paths, which is a positive sign for preventing injection vulnerabilities. The plugin's vulnerability history is also clean, with no recorded CVEs, indicating a history of secure development or timely patching. While the static analysis did not identify any direct vulnerabilities, the complete absence of nonce checks and capability checks across all entry points (though the entry point count is zero) represents a potential concern if the plugin were to evolve and introduce new functionalities that are not adequately protected.

Overall, this plugin presents a low-risk profile due to its limited attack surface, secure coding practices observed in SQL and output handling, and a clean vulnerability history. However, the complete lack of nonce and capability checks, even with the current zero entry points, is a weakness that could become a liability if the plugin's functionality expands in the future.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • 83% of output escaped, 17% not
Vulnerabilities
None known

Spam Prevention for Contact Form 7 and Comments Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Spam Prevention for Contact Form 7 and Comments Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped6 total outputs
Attack Surface

Spam Prevention for Contact Form 7 and Comments Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionplugins_loadedincludes\sitelint-spam-prevention.php:120
actionwp_footerincludes\sitelint-spam-prevention.php:136
actionwp_print_footer_scriptspublic\sitelint-public.php:99
actionwpcf7_before_send_mailpublic\sitelint-public.php:135
actionwpcf7_before_send_mailpublic\sitelint-public.php:152
actionwp_print_footer_scriptspublic\sitelint-public.php:226
actionpre_comment_on_postpublic\sitelint-public.php:227
Maintenance & Trust

Spam Prevention for Contact Form 7 and Comments Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 23, 2025
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Spam Prevention for Contact Form 7 and Comments Developer Profile

ctomczyk

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spam Prevention for Contact Form 7 and Comments

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/spam-prevention-for-contact-form-7-and-comments/public/js/sitelint-public.js
Script Paths
/wp-content/plugins/spam-prevention-for-contact-form-7-and-comments/public/js/sitelint-public.js
Version Parameters
spam-prevention-for-contact-form-7-and-comments/public/js/sitelint-public.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Token for Spam Prevention loaded by SiteLint -->
Data Attributes
data-sitelint-token
JS Globals
window.sitelint_token
FAQ

Frequently Asked Questions about Spam Prevention for Contact Form 7 and Comments