Webhook Configuration CF7 Security & Risk Analysis

wordpress.org/plugins/webhook-configuration-cf7

Use Contact Form 7 as a trigger to any webhook!

100 active installs v1.0.0 PHP 8.0.30+ WP 4.7+ Updated Jun 9, 2024
contact-formcontact-form-7integrationwebhookwebhook-configuration
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Webhook Configuration CF7 Safe to Use in 2026?

Generally Safe

Score 92/100

Webhook Configuration CF7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "webhook-configuration-cf7" plugin, version 1.0.0, exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known vulnerabilities and the lack of critical findings in taint analysis are positive indicators. Furthermore, the plugin demonstrates good coding practices by utilizing prepared statements for all SQL queries and incorporating nonce and capability checks. The attack surface is commendably small, with no exposed AJAX handlers, REST API routes, or shortcodes without authentication. However, a notable concern is the 32% of outputs that are not properly escaped. This could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly rendered without adequate sanitization. While the plugin has no recorded vulnerability history, this is a small version number and a limited history, and the unescaped output represents a potential risk that warrants attention.

Key Concerns

  • Output not properly escaped (68% properly escaped)
Vulnerabilities
None known

Webhook Configuration CF7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Webhook Configuration CF7 Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 16, 2026

Webhook Configuration CF7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
38 escaped
Nonce Checks
9
Capability Checks
1
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

68% escaped56 total outputs
Attack Surface

Webhook Configuration CF7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterwpcf7_editor_panelsmodules\cf7\class-wcc-module-cf7.php:40
actionwpcf7_save_contact_formmodules\cf7\class-wcc-module-cf7.php:41
actionwpcf7_mail_sentmodules\cf7\class-wcc-module-cf7.php:42
filterwpcf7_contact_form_propertiesmodules\cf7\class-wcc-module-cf7.php:44
filterwpcf7_pre_construct_contact_form_propertiesmodules\cf7\class-wcc-module-cf7.php:45
actionadmin_noticesmodules\cf7\class-wcc-module-cf7.php:48
actionwccf7_trigger_webhookmodules\class-wcc-module-webhook.php:40
Maintenance & Trust

Webhook Configuration CF7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedJun 9, 2024
PHP min version8.0.30
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Webhook Configuration CF7 Developer Profile

Ritu Trivedi

1 plugin · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Webhook Configuration CF7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/webhook-configuration-cf7/includes/class-webhook-configuration-cf7.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Webhook Configuration CF7