
User Info In Email For Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/user-info-in-email-for-contact-form-7This plugin is adding the user's internet provider information (based on IP address), to the body of the email. Contact Form 7 Plugin required.
Is User Info In Email For Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100User Info In Email For Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the 'user-info-in-email-for-contact-form-7' plugin version 1.00 exhibits a strong security posture. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and proper output escaping are excellent indicators of secure coding practices. The plugin also has no known CVEs, which further contributes to its positive security profile. However, the presence of an external HTTP request without further context is a potential area of concern. While the attack surface is zero, this external call could be a vector for various attacks if not handled securely, such as SSRF or data exfiltration. The lack of nonce and capability checks, while not explicitly listed as risks in this version due to the zero attack surface, would be significant concerns if new entry points were introduced. Overall, this plugin appears well-secured for its current version, with the main point of attention being the nature and handling of its single external HTTP request.
Key Concerns
- External HTTP requests present
- No nonce checks
- No capability checks
User Info In Email For Contact Form 7 Security Vulnerabilities
User Info In Email For Contact Form 7 Release Timeline
User Info In Email For Contact Form 7 Code Analysis
User Info In Email For Contact Form 7 Attack Surface
WordPress Hooks 1
Maintenance & Trust
User Info In Email For Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
User Info In Email For Contact Form 7 Alternatives
Contact Form 7 Confirm Email Field
contact-form-7-confirm-email-feild
Add a confirm email field to Contact Form 7.
HTML Template for CF7
cf7-html-email-template-extension
Improve your Contact Form 7 emails with a HTML Template.
Contact Form 7 – Blacklist Unwanted Email
block-email-cf7
This is a free add-on plugin for contact form 7, which validates the email field and restrict unwanted email submission as well as allowed only busine …
Dynamic Recipients for Contact Form 7
dynamic-recipients-cf7
Add recipient dropdowns to Contact Form 7. Let visitors route their messages to the right person or department without exposing email addresses.
Conditional Logic Emails and Fields for Contact Form 7
yeekit-conditional-logic-for-contact-form-7
Add conditional logic to Contact Form 7. Show or hide fields and send different emails based on user input.
User Info In Email For Contact Form 7 Developer Profile
1 plugin · 100 total installs
How We Detect User Info In Email For Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[user-info-ip][user-info-city][user-info-state][user-info-country]