
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Security & Risk Analysis
wordpress.org/plugins/wpb-popup-for-contact-form-7Popup for Contact Form 7 can boost your sales, leads, and conversions. It only takes a few clicks to setup a Contact Form 7 Popup on Button Click.
Is WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Safe to Use in 2026?
Generally Safe
Score 98/100WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup has a strong security track record. Known vulnerabilities have been patched promptly.
The "wpb-popup-for-contact-form-7" plugin v2.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and a high percentage of properly escaped output. There are also a reasonable number of nonce checks implemented, which is a positive sign for securing certain actions. The absence of file operations and external HTTP requests further reduces potential attack vectors.
However, there are significant concerns. The presence of two AJAX handlers without authentication checks creates a direct and unprotected entry point for attackers. This, combined with a high number of unprotected total entry points, presents a notable risk. While taint analysis found no issues in this version, the plugin has a history of a high severity "Code Injection" vulnerability, with the last one being quite recent. This historical pattern, even if currently patched, suggests a recurring weakness that requires vigilant monitoring and prompt patching.
In conclusion, while the plugin has implemented some strong security measures, the unprotected AJAX handlers and the past vulnerability in code injection represent critical areas for concern. The historical trend of a high-severity vulnerability demands caution, despite the absence of current unpatched CVEs and the clean taint analysis in this specific version.
Key Concerns
- Unprotected AJAX handlers
- High number of unprotected entry points
- History of high severity code injection vulnerability
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup <= 1.7.5 - Unauthenticated Arbitrary Shortcode Execution via wpb_pcf_fire_contact_form
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 20
Maintenance & Trust
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Maintenance & Trust
Maintenance Signals
Community Trust
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Alternatives
Popup for CF7 with Sweet Alert
cf7-sweet-alert-popup
Popup for CF7 with Sweet Alert
Slick Popup: Contact Form 7 Popup Plugin
slick-popup
A lightweight plugin that converts a Contact Form 7 form into a customizable pop-up form which is slick, beautiful and responsive to different screen …
Form Popup Maker for WPForms, Contact Form 7 and Many other Forms
wpb-form-popup
WPB Popup Form WordPress plugin will help you to create effective form popups. WPForms Popup form, Mailchimp popup, Opt-in, login popup.
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
Website Optimization – Plerdy
plerdy-heatmap
Optimize your website with Plerdy by analyzing traffic sources, scroll depth, user clicks, and usability to enhance conversion and strategy.
WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup Developer Profile
25 plugins · 40K total installs
How We Detect WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpb-popup-for-contact-form-7/assets/css/wpb-popup-for-contact-form-7.css/wp-content/plugins/wpb-popup-for-contact-form-7/assets/js/wpb-popup-for-contact-form-7.js/wp-content/plugins/wpb-popup-for-contact-form-7/assets/js/wpb-popup-for-contact-form-7.jswpb-popup-for-contact-form-7/assets/css/wpb-popup-for-contact-form-7.css?ver=wpb-popup-for-contact-form-7/assets/js/wpb-popup-for-contact-form-7.js?ver=HTML / DOM Fingerprints
wpb-popup-for-contact-form-7wpb-pcf-discount-noticewpb-pcf-form-popup-suggestionwpb-pcf-pro-discount-admin-notice-dismissedwpb-pcf-form-popup-suggestion-admin-notice-dismissed