
WPCasa Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/wpcasa-contact-form-7Add support for Contact Form 7 to attach property details to the contact email sent from WPCasa listing pages.
Is WPCasa Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100WPCasa Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the wpcasa-contact-form-7 plugin version 1.4.0 appears to have a generally strong security posture. The absence of identified dangerous functions, SQL queries without prepared statements, file operations, external HTTP requests, and a lack of recorded vulnerabilities or CVEs are all positive indicators. The plugin also demonstrates good practices in output escaping, with a very high percentage of outputs being properly escaped, minimizing the risk of cross-site scripting (XSS) vulnerabilities.
However, the static analysis reveals a significant concern: zero nonce checks and zero capability checks. This means that while there are no direct entry points like AJAX handlers, REST API routes, shortcodes, or cron events that are immediately visible and unprotected, the lack of these fundamental WordPress security mechanisms leaves the door open for potential privilege escalation or unauthorized actions if any latent functionality were to be triggered. The absence of taint analysis results also means that potential vulnerabilities related to data handling and injection could have been missed.
In conclusion, the plugin's codebase shows adherence to several secure coding practices, and its vulnerability history is clean, which is excellent. The primary weakness lies in the foundational security checks, specifically the lack of nonces and capability checks, which could become a critical vulnerability if new entry points are introduced or if existing, unannounced functionality is exploited. This area requires careful attention to ensure robust security.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Low output escaping (12% unescaped)
WPCasa Contact Form 7 Security Vulnerabilities
WPCasa Contact Form 7 Code Analysis
Output Escaping
WPCasa Contact Form 7 Attack Surface
WordPress Hooks 5
Maintenance & Trust
WPCasa Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
WPCasa Contact Form 7 Alternatives
Contact Form 7 Multi-step Forms (Add-on for CF7)
cf7-multi-step-forms
Contact Form 7 Multi-step Forms helps you add multi-step for your form. This is the best solution to keep the form as simple as possible to your visit …
Contact Form 7 Save to Database (Add-on for CF7)
cf7-save-to-database
Contact Form 7 Save to Database helps you add multi-step for your form. This is the best solution to keep the form as simple as possible to your visit …
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
WPCasa Contact Form 7 Developer Profile
10 plugins · 3K total installs
How We Detect WPCasa Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpcasa-contact-form-7/assets/css/wpsight-contact-form-7.css/wp-content/plugins/wpcasa-contact-form-7/assets/css/wpsight-contact-form-7.min.csswpcasa-contact-form-7/assets/css/wpsight-contact-form-7.css?ver=wpcasa-contact-form-7/assets/css/wpsight-contact-form-7.min.css?ver=HTML / DOM Fingerprints
wpsight-wpcf7<input type="hidden" name="listing_agentlisting_agent_namelisting_id