What the CF7 – Which Contact Form Used In Page/Post Security & Risk Analysis

wordpress.org/plugins/what-the-cf7-which-contact-form-used-in-pagepost

A simple plugin that help you to get contact form id and edit url from current page/post while you are visiting any page or posts. Simple but heloful

0 active installs v1.0.0 PHP + WP 4.0+ Updated Unknown
cf7contact-form-7show-cf7what-cfwhat-the-cf7
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is What the CF7 – Which Contact Form Used In Page/Post Safe to Use in 2026?

Generally Safe

Score 100/100

What the CF7 – Which Contact Form Used In Page/Post has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "what-the-cf7-which-contact-form-used-in-pagepost" v1.0.0 exhibits a generally positive security posture based on the provided static analysis. The absence of identified dangerous functions, raw SQL queries, file operations, external HTTP requests, nonce checks, capability checks, and bundled libraries is commendable. Furthermore, the complete lack of known CVEs and any historical vulnerability data suggests a well-maintained or very niche plugin.

However, a significant concern arises from the output escaping analysis. With one total output and 0% properly escaped, this indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed back to users without proper sanitization can be exploited by attackers to inject malicious scripts, leading to session hijacking, defacement, or redirection to malicious sites. The plugin also has zero attack surface entry points identified, which is unusual and might suggest the analysis might not have fully captured all potential interaction points or that the plugin's functionality is extremely limited.

Key Concerns

  • No output escaping detected
Vulnerabilities
None known

What the CF7 – Which Contact Form Used In Page/Post Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

What the CF7 – Which Contact Form Used In Page/Post Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

What the CF7 – Which Contact Form Used In Page/Post Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_footerwtcf7.php:49
actionadmin_bar_menuwtcf7.php:63
Maintenance & Trust

What the CF7 – Which Contact Form Used In Page/Post Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedUnknown
PHP min version
Downloads845

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

What the CF7 – Which Contact Form Used In Page/Post Developer Profile

Akhtarujjaman Shuvo

10 plugins · 7K total installs

71
trust score
Avg Security Score
89/100
Avg Patch Time
117 days
View full developer profile
Detection Fingerprints

How We Detect What the CF7 – Which Contact Form Used In Page/Post

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
wpcf7-form
JS Globals
wtcf7_admin_url
FAQ

Frequently Asked Questions about What the CF7 – Which Contact Form Used In Page/Post