WCC CF7 to Clio Security & Risk Analysis

wordpress.org/plugins/wcc-cf7-to-clio

Send Contact Form 7 Plugin Submissions to Clio.

0 active installs v1.2.0 PHP 7.2+ WP 4.7+ Updated Apr 18, 2025
cliocontact-form-7-cliocontact-form-7-clio-web-to-leadwordpress-cliowordpress-clio-integration
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is WCC CF7 to Clio Safe to Use in 2026?

Generally Safe

Score 100/100

WCC CF7 to Clio has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The plugin "wcc-cf7-to-clio" v1.2.0 exhibits a generally strong security posture with robust use of prepared statements for SQL queries and proper output escaping. The absence of known vulnerabilities and a clean vulnerability history are significant strengths, indicating a commitment to secure development or a lack of past exploitation. The plugin's attack surface is limited to 8 AJAX handlers, all of which appear to have authentication checks, which is a positive sign. However, the taint analysis reveals 5 high-severity flows with unsanitized paths, which represents a critical concern. These flows, despite not being explicitly labeled as 'critical,' could still lead to severe security issues if exploited. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful scrutiny, especially in conjunction with the unsanitized paths. The lack of capability checks on AJAX handlers, while not explicitly flagged as unprotected, could be a potential area for improvement if the AJAX handlers perform sensitive operations.

Key Concerns

  • High severity taint flows with unsanitized paths
  • File operations present, warrants scrutiny
  • External HTTP requests present, warrants scrutiny
Vulnerabilities
None known

WCC CF7 to Clio Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WCC CF7 to Clio Code Analysis

Dangerous Functions
0
Raw SQL Queries
9
58 prepared
Unescaped Output
21
442 escaped
Nonce Checks
23
Capability Checks
0
File Operations
1
External Requests
8
Bundled Libraries
0

SQL Query Safety

87% prepared67 total queries

Output Escaping

95% escaped463 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

10 flows5 with unsanitized paths
wcc_cf7_clio_get_module_fields (Inc\WccCf7Clio_Actions.php:159)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WCC CF7 to Clio Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 8

noprivwp_ajax_wcc_cf7_clio_get_module_fieldsInc\WccCf7Clio_Actions.php:58
authwp_ajax_wcc_cf7_clio_get_module_fieldsInc\WccCf7Clio_Actions.php:59
noprivwp_ajax_wcc_cf7_clio_get_module_fields_and_form_fieldInc\WccCf7Clio_Actions.php:62
authwp_ajax_wcc_cf7_clio_get_module_fields_and_form_fieldInc\WccCf7Clio_Actions.php:63
noprivwp_ajax_wcc_cf7_clio_get_coinditions_fieldsInc\WccCf7Clio_Actions.php:66
authwp_ajax_wcc_cf7_clio_get_coinditions_fieldsInc\WccCf7Clio_Actions.php:67
noprivwp_ajax_wcc_cf7_clio_statusInc\WccCf7Clio_Actions.php:70
authwp_ajax_wcc_cf7_clio_statusInc\WccCf7Clio_Actions.php:72
WordPress Hooks 7
actioninitInc\WccCf7Clio_Actions.php:37
actionadmin_enqueue_scriptsInc\WccCf7Clio_Actions.php:43
actionadmin_menuInc\WccCf7Clio_Actions.php:45
actionadmin_menuInc\WccCf7Clio_Actions.php:46
actionwcc_entries_form_cf7_submit_actionInc\WccCf7Clio_Actions.php:51
actionwpcf7_before_send_mailInc\WccCf7Clio_Actions.php:53
actionwcc_entries_below_view_page_leftInc\WccCf7Clio_Actions.php:74
Maintenance & Trust

WCC CF7 to Clio Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 18, 2025
PHP min version7.2
Downloads912

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

WCC CF7 to Clio Developer Profile

weconnectcodeplugins

11 plugins · 10 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WCC CF7 to Clio

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wcc-cf7-to-clio/assets/css/frontend.css/wp-content/plugins/wcc-cf7-to-clio/assets/js/frontend.js
Script Paths
/wp-content/plugins/wcc-cf7-to-clio/assets/js/frontend.js
Version Parameters
wcc-cf7-to-clio/assets/css/frontend.css?ver=wcc-cf7-to-clio/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wcc-cf7-clio-settings-wrapwcc-cf7-clio-frontend-wrapwcc-cf7-clio-form-wrap
HTML Comments
<!-- WCC CF7 to Clio Plugin --><!-- WCC CF7 to Clio Settings Page -->
Data Attributes
data-wcc-cf7-clio-actiondata-wcc-cf7-clio-module
JS Globals
WCC_CF7_CLIO_AJAX_URLWCC_CF7_CLIO_PLUGIN_URL
REST Endpoints
/wp-json/wcc-cf7-clio/v1/settings/wp-json/wcc-cf7-clio/v1/sync
Shortcode Output
<div class="wcc-cf7-clio-form-wrap"><form id="wcc-cf7-clio-form" action="" method="post">
FAQ

Frequently Asked Questions about WCC CF7 to Clio