Star Rating Field For Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/star-rating-field-for-contact-form-7

Star Rating Field to Contact Form 7 is free plugin. Star Rating Fields are added to Contact Form 7 by this plugin. Select a Rating style from 12 ava …

900 active installs v1.0 PHP + WP 5.5+ Updated May 12, 2025
contact-form-7rating-field-contact-form-7
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Star Rating Field For Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 92/100

Star Rating Field For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "star-rating-field-for-contact-form-7" plugin, version 1.0, exhibits a generally strong security posture based on the provided static analysis. The absence of any known CVEs, particularly critical or high severity ones, along with no recorded vulnerabilities, is a significant positive indicator. The code analysis reveals no dangerous functions, no file operations, no external HTTP requests, and no SQL queries that aren't using prepared statements. This suggests a careful approach to developing the plugin's core functionality.

However, there are areas that warrant attention. The plugin has no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a zero attack surface from these common entry points. While this is good, the lack of any capability checks or nonce checks across the board is a concern. Even with a minimal attack surface, these checks are fundamental security practices that protect against potential unauthorized actions or cross-site request forgery (CSRF) if functionality were to be added or modified in the future.

Furthermore, while the majority of output escaping is properly handled, the 15% of outputs that are not properly escaped could present a Cross-Site Scripting (XSS) risk if untrusted data is displayed. The taint analysis returning zero flows is excellent, but this should be viewed in conjunction with the lack of other security mechanisms. The overall impression is of a plugin that has been developed with some security awareness, but lacks some fundamental protective measures that are standard in robust WordPress plugin development.

Key Concerns

  • No capability checks present
  • No nonce checks present
  • Some outputs are not properly escaped
Vulnerabilities
None known

Star Rating Field For Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Star Rating Field For Contact Form 7 Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Star Rating Field For Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped13 total outputs
Attack Surface

Star Rating Field For Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwpcf7_admin_initincludes\admin.php:2
actionwpcf7_initincludes\frontend.php:2
filterwpcf7_validate_star_ratingincludes\frontend.php:38
filterwpcf7_validate_star_rating*includes\frontend.php:39
actionwp_enqueue_scriptsstar-rating-field-for-contact-form-7.php:42
Maintenance & Trust

Star Rating Field For Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 12, 2025
PHP min version
Downloads4K

Community Trust

Rating46/100
Number of ratings3
Active installs900
Developer Profile

Star Rating Field For Contact Form 7 Developer Profile

howdytheme

20 plugins · 5K total installs

90
trust score
Avg Security Score
94/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Star Rating Field For Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/star-rating-field-for-contact-form-7/public/jquery.rating/jquery.raty.js/wp-content/plugins/star-rating-field-for-contact-form-7/public/js/design.js/wp-content/plugins/star-rating-field-for-contact-form-7/public/jquery.rating/jquery.raty.css
Version Parameters
star-rating-field-for-contact-form-7/public/jquery.rating/jquery.raty.js?ver=star-rating-field-for-contact-form-7/public/js/design.js?ver=star-rating-field-for-contact-form-7/public/jquery.rating/jquery.raty.css?ver=

HTML / DOM Fingerprints

CSS Classes
srffcf7_pro_msg
Data Attributes
data-tag-partdata-tag-option
JS Globals
student_ajax
Shortcode Output
star_rating
FAQ

Frequently Asked Questions about Star Rating Field For Contact Form 7