
WP Forms Connector Security & Risk Analysis
wordpress.org/plugins/wp-forms-connectorShort Description: Easily manage and export Contact Form 7 submissions via REST API.
Is WP Forms Connector Safe to Use in 2026?
Generally Safe
Score 100/100WP Forms Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-forms-connector" plugin v1.8 presents a mixed security posture. On the positive side, it has no known CVEs and boasts a good number of capability checks. However, the static analysis reveals some significant areas of concern. The presence of the `unserialize` function is a major red flag, as it's a common vector for remote code execution if data is not properly sanitized before being passed to it. While taint analysis did not report critical or high severity flows, the presence of "flows with unsanitized paths" is concerning and warrants further investigation. The fact that one REST API route lacks a permission callback is a direct entry point that could be exploited by unauthenticated users. The plugin also has a substantial percentage of SQL queries not using prepared statements, increasing the risk of SQL injection vulnerabilities. Despite these risks, the plugin's lack of historical vulnerabilities might suggest a diligent development team or a less targeted attack surface, but the current code signals suggest proactive patching and scrutiny are essential.
Key Concerns
- REST API route without permission callback
- Dangerous function: unserialize found
- SQL queries not using prepared statements (69%)
- Output escaping not properly implemented (38%)
- Flows with unsanitized paths found
WP Forms Connector Security Vulnerabilities
WP Forms Connector Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Forms Connector Attack Surface
REST API Routes 2
WordPress Hooks 20
Maintenance & Trust
WP Forms Connector Maintenance & Trust
Maintenance Signals
Community Trust
WP Forms Connector Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
Bootstrap for Contact Form 7
bootstrap-for-contact-form-7
This plugin modifies the output of the popular Contact Form 7 plugin to be styled in compliance with themes using the Bootstrap CSS framework.
Contact Form to Any API
contact-form-to-any-api
Send Contact Form 7 submissions to any API, Webhook or CRM - quick setup, flexible payloads, endpoints and authentication.
Contact Form 7: Accessible Defaults
contact-form-7-accessible-defaults
Replaces the default Contact Form 7 form with an accessible equivalent and provides a suite of selectable base forms.
Date Picker For Contact Form 7
date-picker-for-contact-form-7
Easily add a customizable Date Picker to Contact Form 7. Restrict dates, disable specific days, and improve your booking forms.
WP Forms Connector Developer Profile
4 plugins · 60 total installs
How We Detect WP Forms Connector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-forms-connector/assets/css/admin-style.cssHTML / DOM Fingerprints
wrapicon32class="row-title"