Styler for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/styler-for-contact-form-7

Styler for Contact Form 7 helps you to create beautiful designs without CSS Coding.

40 active installs v1.1 PHP + WP 4.0+ Updated Apr 6, 2017
contact-form-7contact-form-7-csscontact-form-7-designcontact-form-7-layoutcontact-form-7-styler
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Styler for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

Styler for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The plugin "styler-for-contact-form-7" v1.1 demonstrates a generally good security posture with no reported vulnerabilities or critical code signals. The absence of known CVEs and a clean vulnerability history are positive indicators. Furthermore, the static analysis reveals no direct attack vectors like unprotected AJAX handlers, REST API routes, shortcodes, or cron events. The plugin also avoids dangerous functions, raw SQL queries, and file operations, all of which are strong security practices.

However, there are areas for improvement. The low percentage of properly escaped output (37%) is a significant concern, as it suggests potential for cross-site scripting (XSS) vulnerabilities, especially if user-supplied data is being outputted without sufficient sanitization. While taint analysis shows no critical or high severity flows, this could be due to limited analysis scope or the absence of complex data flows. The single external HTTP request also warrants attention; without further context, it's difficult to assess its security implications, but it could be an entry point for certain attacks if not handled securely.

In conclusion, the plugin's foundation appears solid due to the lack of critical vulnerabilities and responsible coding practices in core areas. Nevertheless, the unescaped output presents a notable risk that should be addressed promptly. The plugin developers should prioritize improving output escaping and ensuring all external requests are secured.

Key Concerns

  • Low percentage of properly escaped output
  • One external HTTP request without context
Vulnerabilities
None known

Styler for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Styler for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
16 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

37% escaped43 total outputs
Attack Surface

Styler for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadmin_menuadmin-menu\addons.php:6
actionadmin_enqueue_scriptsadmin-menu\addons.php:12
actionadmin_initadmin-menu\EDD_SL_Plugin_Updater.php:41
filterpre_set_site_transient_update_pluginsadmin-menu\EDD_SL_Plugin_Updater.php:53
filterplugins_apiadmin-menu\EDD_SL_Plugin_Updater.php:54
filterpre_set_site_transient_update_pluginsadmin-menu\EDD_SL_Plugin_Updater.php:169
actionadmin_menuadmin-menu\licenses.php:6
actionadmin_initadmin-menu\licenses.php:7
actionadmin_menuadmin-menu\welcome-page.php:6
actioncustomize_registerstyler-for-contact-form7.php:43
actioncustomize_controls_enqueue_scriptsstyler-for-contact-form7.php:44
actioncustomize_preview_initstyler-for-contact-form7.php:45
actionadmin_initstyler-for-contact-form7.php:47
actionwpcf7_contact_formstyler-for-contact-form7.php:51
Maintenance & Trust

Styler for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedApr 6, 2017
PHP min version
Downloads4K

Community Trust

Rating80/100
Number of ratings2
Active installs40
Developer Profile

Styler for Contact Form 7 Developer Profile

wpmonks

6 plugins · 71K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Styler for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/styler-for-contact-form-7/js/auto-save-form.js/wp-content/plugins/styler-for-contact-form-7/js/live-preview-changes.js
Script Paths
/wp-content/plugins/styler-for-contact-form-7/js/auto-save-form.js/wp-content/plugins/styler-for-contact-form-7/js/live-preview-changes.js
Version Parameters
styler-for-contact-form-7/js/auto-save-form.js?ver=styler-for-contact-form-7/js/live-preview-changes.js?ver=

HTML / DOM Fingerprints

CSS Classes
cf_styler_select_form_section
HTML Comments
<!-- Main class of Styles & layouts Gravity Forms --><!-- don't load directly --><!-- detect contact form 7 --><!-- Removed in v1.1 -->+6 more
Data Attributes
id="cf_styler_hidden_field_for_form_id"
JS Globals
formId
FAQ

Frequently Asked Questions about Styler for Contact Form 7