SPIRAL Connector for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/spiral-connector-for-contact-form-7

A WordPress plugin that integrates Contact Form 7 with SPIRAL®., securely storing submitted form data and safely delivering emails via SPIRAL®..

0 active installs v1.0 PHP + WP 6.9+ Updated Unknown
contact-form-7email-deliverabilityform-databasespam-protectionspiral
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SPIRAL Connector for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

SPIRAL Connector for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The spiral-connector-for-contact-form-7 v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. All identified AJAX handlers, which represent the primary attack surface, are protected by nonce checks and capability checks. The absence of dangerous functions, raw SQL queries, unsanitized taint flows, and file operations further reinforces this positive assessment. The plugin also demonstrates good practices with 100% output escaping and the use of prepared statements for SQL, which significantly mitigates the risk of common vulnerabilities like SQL injection and cross-site scripting. The lack of any recorded vulnerabilities in its history is also a positive indicator of diligent security practices during development.

However, the plugin does make a significant number of external HTTP requests (9) without explicit mention of authentication or validation of the responses. This is the most notable area of concern, as these requests could potentially be exploited if the remote endpoints are compromised or if the data returned is not properly sanitized before being used within the WordPress environment. While the static analysis did not reveal specific exploitable flaws in these requests, they represent a potential vector for indirect vulnerabilities or information leakage if not handled with extreme care. The absence of taint analysis data is a minor limitation, as it prevents a deeper inspection of data flow, but the otherwise clean code signals suggest this may not be a significant omission for this particular version. Overall, the plugin appears to be developed with security in mind, but the external HTTP requests warrant careful review and ongoing monitoring.

Key Concerns

  • External HTTP requests without clear validation
Vulnerabilities
None known

SPIRAL Connector for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SPIRAL Connector for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
42 escaped
Nonce Checks
9
Capability Checks
11
File Operations
0
External Requests
9
Bundled Libraries
0

Output Escaping

100% escaped42 total outputs
Attack Surface

SPIRAL Connector for Contact Form 7 Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_scfcf7_db_createajax\editor\create-db.php:5
authwp_ajax_scfcf7_db_getajax\editor\sources.php:5
authwp_ajax_scfcf7_db_checkajax\editor\update-db.php:5
authwp_ajax_scfcf7_get_appsajax\setting\applist.php:5
WordPress Hooks 26
filterwpcf7_editor_panelseditor\editor.php:16
actionwpcf7_admin_noticeseditor\editor.php:27
actionsave_post_wpcf7_contact_formeditor\editor.php:245
filterwpcf7_spamsend\send.php:30
filterwpcf7_skip_mailsend\send.php:39
filterwpcf7_validate_textsend\send.php:252
filterwpcf7_validate_text*send\send.php:253
filterwpcf7_validate_emailsend\send.php:254
filterwpcf7_validate_email*send\send.php:255
filterwpcf7_validate_urlsend\send.php:256
filterwpcf7_validate_url*send\send.php:257
filterwpcf7_validate_textareasend\send.php:258
filterwpcf7_validate_textarea*send\send.php:259
filterwpcf7_validate_numbersend\send.php:260
filterwpcf7_validate_number*send\send.php:261
filterwpcf7_validate_datesend\send.php:262
filterwpcf7_validate_date*send\send.php:263
filterwpcf7_validate_telsend\send.php:264
filterwpcf7_validate_tel*send\send.php:265
filterwpcf7_display_messagesend\send.php:316
actionplugins_loadedsetting\admin-setup.php:5
actionadmin_menusetting\admin-setup.php:7
actionadmin_post_scfcf7_accountidsetting\admin-setup.php:59
actionadmin_post_scfcf7_selectappsetting\admin-setup.php:88
actionadmin_post_scfcf7_securitysetting\admin-setup.php:125
actionadmin_post_scfcf7_updateappsetting\admin-setup.php:165
Maintenance & Trust

SPIRAL Connector for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version
Downloads177

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SPIRAL Connector for Contact Form 7 Developer Profile

SPIRAL Inc.

2 plugins · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SPIRAL Connector for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/spiral-connector-for-contact-form-7/setting/assets/css/setting.css/wp-content/plugins/spiral-connector-for-contact-form-7/setting/assets/js/setting.js/wp-content/plugins/spiral-connector-for-contact-form-7/setting/assets/js/app.js
Version Parameters
spiral-connector-for-contact-form-7/setting/assets/css/setting.css?ver=spiral-connector-for-contact-form-7/setting/assets/js/setting.js?ver=spiral-connector-for-contact-form-7/setting/assets/js/app.js?ver=

HTML / DOM Fingerprints

CSS Classes
scfcf7_headerstep_lineactive
Data Attributes
scfcf7_ajax
JS Globals
scfcf7_ajax
FAQ

Frequently Asked Questions about SPIRAL Connector for Contact Form 7