
Star Rating Field For Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/star-rating-field-for-contact-form-7Star Rating Field to Contact Form 7 is free plugin. Star Rating Fields are added to Contact Form 7 by this plugin. Select a Rating style from 12 ava …
Is Star Rating Field For Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 92/100Star Rating Field For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "star-rating-field-for-contact-form-7" plugin, version 1.0, exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs, particularly critical or high severity ones, along with no recorded vulnerabilities, is a significant positive indicator. The code analysis reveals no dangerous functions, no file operations, no external HTTP requests, and no SQL queries that aren't using prepared statements. This suggests a careful approach to developing the plugin's core functionality.
However, there are areas that warrant attention. The plugin has no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface from these common entry points. While this is good, the lack of any capability checks or nonce checks across the board is a concern. Even with a minimal attack surface, these checks are fundamental security practices that protect against potential unauthorized actions or cross-site request forgery (CSRF) if functionality were to be added or modified in the future.
Furthermore, while the majority of output escaping is properly handled, the 15% of outputs that are not properly escaped could present a Cross-Site Scripting (XSS) risk if untrusted data is displayed. The taint analysis returning zero flows is excellent, but this should be viewed in conjunction with the lack of other security mechanisms. The overall impression is of a plugin that has been developed with some security awareness, but lacks some fundamental protective measures that are standard in robust WordPress plugin development.
Key Concerns
- No capability checks present
- No nonce checks present
- Some outputs are not properly escaped
Star Rating Field For Contact Form 7 Security Vulnerabilities
Star Rating Field For Contact Form 7 Release Timeline
Star Rating Field For Contact Form 7 Code Analysis
Output Escaping
Star Rating Field For Contact Form 7 Attack Surface
WordPress Hooks 5
Maintenance & Trust
Star Rating Field For Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Star Rating Field For Contact Form 7 Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 – Dynamic Text Extension
contact-form-7-dynamic-text-extension
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
Star Rating Field For Contact Form 7 Developer Profile
20 plugins · 5K total installs
How We Detect Star Rating Field For Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/star-rating-field-for-contact-form-7/public/jquery.rating/jquery.raty.js/wp-content/plugins/star-rating-field-for-contact-form-7/public/js/design.js/wp-content/plugins/star-rating-field-for-contact-form-7/public/jquery.rating/jquery.raty.cssstar-rating-field-for-contact-form-7/public/jquery.rating/jquery.raty.js?ver=star-rating-field-for-contact-form-7/public/js/design.js?ver=star-rating-field-for-contact-form-7/public/jquery.rating/jquery.raty.css?ver=HTML / DOM Fingerprints
srffcf7_pro_msgdata-tag-partdata-tag-optionstudent_ajaxstar_rating