Success Fail Popup Message For Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/success-fail-popup-message-for-contact-form-7

Success Fail Popup Message For Contact Form 7 to make the best way to set up poup on success and failed messages so a visitor will be attracted to tha …

100 active installs v1.0 PHP 5.0+ WP + Updated Jan 31, 2026
contact-form-7error-popup-messagepopup-message-contact-form-7success-fail-popupsuccess-popup-message
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Success Fail Popup Message For Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Success Fail Popup Message For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "success-fail-popup-message-for-contact-form-7" plugin, version 1.0, presents a generally positive security posture based on the provided static analysis. The plugin exhibits no known CVEs, indicating a history of responsible development or a lack of past discovered vulnerabilities. Furthermore, the absence of dangerous functions, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are excellent security practices.

However, there are notable areas of concern. The lack of any capability checks or nonce checks across all entry points is a significant weakness. While the attack surface appears to be zero in terms of AJAX, REST API, shortcodes, and cron events, this absence of security checks means that any *future* introduction of such entry points would be inherently unprotected. Additionally, a concerning 45% of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is ever incorporated into these outputs without adequate sanitization.

The taint analysis shows two flows with unsanitized paths, though they are not classified as critical or high severity. This suggests potential weaknesses in data handling that, while not currently exploited, warrant attention to prevent future issues. In conclusion, while the plugin has a clean vulnerability history and uses good practices in areas like SQL, the lack of robust access controls and significant unescaped output represent critical security gaps that need immediate remediation.

Key Concerns

  • No capability checks on entry points
  • No nonce checks on entry points
  • Significant unescaped output (45%)
  • Taint flows with unsanitized paths
Vulnerabilities
None known

Success Fail Popup Message For Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Success Fail Popup Message For Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
36
44 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

55% escaped80 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
SFPMCF7_wpcf7_editor_panel_popup (main\backend\success_fail_popup_options.php:22)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Success Fail Popup Message For Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
filterwpcf7_editor_panelsmain\backend\success_fail_popup_options.php:9
actionadmin_footermain\backend\success_fail_popup_options.php:286
actionwpcf7_after_savemain\backend\success_fail_popup_options.php:375
filterwpcf7_ajax_json_echomain\frontend\success_fail_submit_popup_settings.php:9
actionadmin_initmain\resources\success-fail-popup-installation-require.php:3
actionadmin_noticesmain\resources\success-fail-popup-installation-require.php:11
actionplugins_loadedmain\resources\success-fail-popup-language.php:4
filterload_textdomain_mofilemain\resources\success-fail-popup-language.php:18
actionadmin_enqueue_scriptsmain\resources\success-fail-popup-load-js-css.php:4
actionwp_enqueue_scriptsmain\resources\success-fail-popup-load-js-css.php:26
filterplugin_row_metasuccess_fail_popup_message_cf7.php:43
Maintenance & Trust

Success Fail Popup Message For Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 31, 2026
PHP min version5.0
Downloads2K

Community Trust

Rating46/100
Number of ratings3
Active installs100
Developer Profile

Success Fail Popup Message For Contact Form 7 Developer Profile

silverplugins217

21 plugins · 12K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect Success Fail Popup Message For Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/success-fail-popup-message-for-contact-form-7/assets/css/backend.css/wp-content/plugins/success-fail-popup-message-for-contact-form-7/assets/js/wp_media_uploader.js/wp-content/plugins/success-fail-popup-message-for-contact-form-7/assets/js/wp-color-picker-alpha.js/wp-content/plugins/success-fail-popup-message-for-contact-form-7/assets/js/success_fail_popupscript.js/wp-content/plugins/success-fail-popup-message-for-contact-form-7/assets/js/sweetalert2.all.min.js/wp-content/plugins/success-fail-popup-message-for-contact-form-7/assets/css/sweetalert2.min.css/wp-content/plugins/success-fail-popup-message-for-contact-form-7/assets/css/front.css
Script Paths
success_fail_popup_message_cf7.php
Version Parameters
success-fail-popup-message-for-contact-form-7/assets/css/backend.css?ver=success-fail-popup-message-for-contact-form-7/assets/js/wp_media_uploader.js?ver=success-fail-popup-message-for-contact-form-7/assets/js/wp-color-picker-alpha.js?ver=success-fail-popup-message-for-contact-form-7/assets/js/success_fail_popupscript.js?ver=success-fail-popup-message-for-contact-form-7/assets/js/sweetalert2.all.min.js?ver=success-fail-popup-message-for-contact-form-7/assets/css/sweetalert2.min.css?ver=success-fail-popup-message-for-contact-form-7/assets/css/front.css?ver=

HTML / DOM Fingerprints

CSS Classes
tbl_maintbl_child
Data Attributes
sfpmcf7_enabled_popup_valsfpmcf7_popup_messagesfpmcf7_m_popup_widthsfpmcf7_m_popup_radiussfpmcf7_m_popup_duration
JS Globals
wpColorPickerL10n
FAQ

Frequently Asked Questions about Success Fail Popup Message For Contact Form 7