Svetlik Analytics for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/svetlik-analytics-for-contact-form-7

View analytics and insights for Contact Form 7 submissions directly in your WordPress dashboard.

0 active installs v1.0.3 PHP + WP 6.0+ Updated Feb 8, 2026
contact-form-analyticsform-analyticsstatisticssubmissionssvetlik
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Svetlik Analytics for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Svetlik Analytics for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "svetlik-analytics-for-contact-form-7" v1.0.3 exhibits a generally strong security posture based on the provided static analysis. The absence of a significant attack surface, dangerous functions, file operations, and external HTTP requests is a positive indicator. The plugin also demonstrates good practices with 100% output escaping and a high percentage of prepared statements for SQL queries. The presence of a nonce check and capability checks further bolsters its security, suggesting an effort to protect against common web vulnerabilities.

However, the taint analysis reveals a concerning flow with an unsanitized path, classified as high severity. While the static analysis shows no direct vulnerabilities like unescaped output or raw SQL, this single high-severity taint flow represents a potential avenue for exploitation if not properly handled internally within the plugin's logic. The lack of any historical vulnerabilities is a significant strength, indicating a mature and relatively stable codebase in terms of past security issues. This suggests the developers have been diligent in addressing past problems or have avoided introducing them in the first place.

In conclusion, while the plugin has a strong foundation in secure coding practices and a clean vulnerability history, the identified high-severity taint flow is a specific area of concern that warrants investigation. It indicates a potential blind spot in how data is handled, which could be exploited under specific circumstances. Therefore, immediate attention should be paid to this particular taint flow to ensure it does not lead to a real-world vulnerability.

Key Concerns

  • High severity taint flow with unsanitized path
Vulnerabilities
None known

Svetlik Analytics for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Svetlik Analytics for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
22 prepared
Unescaped Output
0
39 escaped
Nonce Checks
1
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

96% prepared23 total queries

Output Escaping

100% escaped39 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<class-analytics-service> (includes\analytics\class-analytics-service.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Svetlik Analytics for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuincludes\admin\class-admin-page.php:13
actionadmin_enqueue_scriptsincludes\admin\class-admin-page.php:14
actionwp_dashboard_setupincludes\admin\class-dashboard-widget.php:8
actionadmin_noticesincludes\class-dependency-check.php:10
actionplugins_loadedincludes\class-plugin.php:14
actionwpcf7_submitincludes\class-tracker.php:10
Maintenance & Trust

Svetlik Analytics for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 8, 2026
PHP min version
Downloads132

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Svetlik Analytics for Contact Form 7 Developer Profile

Jaroslav Svetlik

4 plugins · 40 total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Svetlik Analytics for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/svetlik-analytics-for-contact-form-7/assets/css/admin.css/wp-content/plugins/svetlik-analytics-for-contact-form-7/assets/js/admin.js
Script Paths
/wp-content/plugins/svetlik-analytics-for-contact-form-7/assets/vendor/chart/chart.min.js/wp-content/plugins/svetlik-analytics-for-contact-form-7/assets/js/admin.js
Version Parameters
svetlik-analytics-for-contact-form-7/assets/css/admin.css?ver=svetlik-analytics-for-contact-form-7/assets/js/admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Svetlik Analytics for Contact Form 7