
Ultra Addons for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/ultimate-addons-for-contact-form-750+ Essential Addons for Contact Form 7 - Conditional Fields, Multi Step, Redirection, Columns, WooCommerce, Mailchimp & more
Is Ultra Addons for Contact Form 7 Safe to Use in 2026?
Mostly Safe
Score 82/100Ultra Addons for Contact Form 7 is generally safe to use. 14 past CVEs were resolved.
The "ultimate-addons-for-contact-form-7" plugin v3.5.38 presents a mixed security posture. While it demonstrates good practices like a high percentage of SQL prepared statements and proper output escaping, several areas raise concerns. The static analysis reveals a substantial attack surface, with 10 out of 40 entry points lacking authentication checks. This is exacerbated by four instances of the dangerous `unserialize` function, which can lead to remote code execution if not handled with extreme care. The taint analysis further highlights critical risks, with four high-severity flows indicating potential vulnerabilities where user-controlled input is not properly sanitized before being used in sensitive operations. The plugin's history of 13 CVEs, including a past critical vulnerability, is a significant red flag. Although there are currently no unpatched CVEs, the prevalence of past vulnerabilities in common types like missing authorization and SQL injection suggests recurring security weaknesses. The presence of bundled libraries like Select2 and TCPDF also warrants attention, as these could introduce their own vulnerabilities if outdated or misconfigured. In conclusion, while the plugin shows effort in secure coding, the combination of a large unprotected attack surface, potentially dangerous functions, concerning taint flows, and a history of numerous vulnerabilities necessitates careful consideration and vigilant monitoring.
Key Concerns
- 10 AJAX handlers without auth checks
- 4 instances of 'unserialize' function
- 4 high severity taint flows
- 13 total known CVEs historically
- 1 critical past vulnerability
- Bundled libraries (Select2, TCPDF)
Ultra Addons for Contact Form 7 Security Vulnerabilities
CVEs by Year
Severity Breakdown
14 total CVEs
Ultra Addons for Contact Form 7 <= 3.5.36 - Authenticated (Contributor+) Stored Cross-Site Scripting
Ultimate Addons for Contact Form 7 <= 3.5.34 - Missing Authorization
Ultra Addons for Contact Form 7 <= 3.5.33 - Missing Authorization to Authenticated (Subscriber+) to Generate Form Submission PDF
Ultra Addons for Contact Form 7 <= 3.5.21 - Authenticated (Contributor+) Stored Cross-Site Scripting via UACF7_CUSTOM_FIELDS Shortcode
Ultra Addons for Contact Form 7 3.5.11 - 3.5.19 - Unauthenticated Stored Cross-Site Scripting via Database module
Ultimate Addons for Contact Form 7 <= 3.5.12 - Authenticated (Administrator+) Arbitrary File Upload via 'save_options'
Ultimate Addons for Contact Form 7 <= 3.2.0 - Reflected Cross-Site Scripting
Ultimate Addons for Contact Form 7 <= 3.2.10 - Missing Authorization
Ultimate Addons for Contact Form 7 <= 3.1.0 - Reflected Cross-Site Scripting via 'page'
Ultimate Addons for Contact Form 7 <= 3.1.28 - Reflected Cross-Site Scripting
Ultimate Addons for Contact Form 7 <= 3.1.28 - Authenticated (Admin+) Stored Cross-Site Scripting
Ultimate Addons for Contact Form 7 <= 3.1.23 - Authenticated(Subscriber+) SQL Injection
Ultimate Addons for Contact Form 7 <= 3.1.23 - Unauthenticated SQL Injection via form_id
Ultimate Addons for Contact Form 7 <= 3.1.23 - Authenticated (Subscriber+) SQL Injection via id
Ultra Addons for Contact Form 7 Release Timeline
Ultra Addons for Contact Form 7 Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Ultra Addons for Contact Form 7 Attack Surface
AJAX Handlers 34
Shortcodes 6
WordPress Hooks 169
Scheduled Events 1
Maintenance & Trust
Ultra Addons for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Ultra Addons for Contact Form 7 Alternatives
Origami For Contact Form 7 – Visual Form Progress
origami-for-contact-form-7
Tired of boring forms? Enhance your Contact Form 7 with interactive origami animations, making form-filling fun and engaging!
WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More
wpforms-lite
The best WordPress contact form plugin. Drag & Drop form builder to create beautiful contact forms, payment forms, & other custom forms.
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
fluentform
Get a fast contact form plugin. Create advanced forms using drag and drop form builder with all smart features.
SureForms – Contact Form, Payment Form & Other Custom Form Builder
sureforms
The most beginner-friendly AI Form Builder for WordPress. Create contact, payment, quiz & custom forms with advanced features in minutes.
Everest Forms – Contact Form, Payment Form, Quiz, Survey & Custom Form Builder
everest-forms
The best WordPress form builder. Create contact forms, payment forms, conversational forms, custom forms, surveys, & quizzes using drag and drop.
Ultra Addons for Contact Form 7 Developer Profile
11 plugins · 97K total installs
How We Detect Ultra Addons for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ultimate-addons-for-contact-form-7/assets/css/admin-style.css/wp-content/plugins/ultimate-addons-for-contact-form-7/assets/js/admin-script.js/wp-content/plugins/ultimate-addons-for-contact-form-7/assets/app/libs/notyf/notyf.min.css/wp-content/plugins/ultimate-addons-for-contact-form-7/assets/app/libs/notyf/notyf.min.js/wp-content/plugins/ultimate-addons-for-contact-form-7/assets/css/uacf7-frontend.css/wp-content/plugins/ultimate-addons-for-contact-form-7/assets/css/form-style.css/wp-content/plugins/ultimate-addons-for-contact-form-7/assets/js/admin-script.js/wp-content/plugins/ultimate-addons-for-contact-form-7/assets/app/libs/notyf/notyf.min.jsultimate-addons-for-contact-form-7/assets/app/libs/notyf/notyf.min.css?ver=ultimate-addons-for-contact-form-7/assets/app/libs/notyf/notyf.min.js?ver=HTML / DOM Fingerprints
uacf7-admin-styleuacf7-frontend-styleuacf7-form-styledata-noncedata-uacf7_admin_noncedata-themefic_noncedata-uacf7_admin_paramsuacf7_optionsuacf7_admin_datauacf7_admin_params