Active Campaign & Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/wpop-accf

Add Contact Form 7 Data to ActiveCampaign Contact lists.

3K active installs v1.2.3 PHP 7.4+ WP 5.6+ Updated Jun 10, 2025
active-campaignactivecampaigncf7-active-campaigncontact-form-7subscription-list
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Active Campaign & Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Active Campaign & Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "wpop-accf" v1.2.3 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events suggests a limited attack surface. Furthermore, the complete utilization of prepared statements for SQL queries and the lack of identified dangerous functions are significant strengths. The absence of any recorded vulnerabilities or CVEs in its history also contributes positively to its security profile.

However, there are areas of concern that warrant attention. The fact that only 30% of output is properly escaped indicates a substantial risk of cross-site scripting (XSS) vulnerabilities. This is particularly concerning given the lack of explicit capability checks and nonce checks on potential entry points, although the static analysis reports zero entry points. The single external HTTP request, while not inherently a vulnerability, should be carefully scrutinized to ensure it is not exploitable. The lack of any taint analysis findings could be due to the limited scope of the analysis or the plugin's actual design, but combined with the unescaped output, it presents a potential blind spot.

In conclusion, while the plugin demonstrates good practices in areas like SQL query handling and has a clean vulnerability history, the significant percentage of unescaped output presents a notable risk. The absence of identified entry points and vulnerabilities is a positive sign, but the unescaped output remains the most pressing concern from the provided data. Further manual code review of the output handling mechanisms and the external HTTP request would be prudent.

Key Concerns

  • Low percentage of properly escaped output
  • No capability checks on potential entry points
  • No nonce checks on potential entry points
  • External HTTP request without specific analysis
Vulnerabilities
None known

Active Campaign & Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Active Campaign & Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
40
17 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

30% escaped57 total outputs
Attack Surface

Active Campaign & Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterwpcf7_editor_panelsincludes\accf7-settings.php:7
actionsave_post_wpcf7_contact_formincludes\accf7-settings.php:8
actionwpcf7_before_send_mailincludes\accf7-subscribe.php:7
actioninitwpop-accf.php:24
actionadmin_enqueue_scriptswpop-accf.php:25
actioninitwpop-accf.php:26
actionadmin_noticeswpop-accf.php:36
Maintenance & Trust

Active Campaign & Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 10, 2025
PHP min version7.4
Downloads86K

Community Trust

Rating88/100
Number of ratings18
Active installs3K
Developer Profile

Active Campaign & Contact Form 7 Developer Profile

wpoperations

9 plugins · 17K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
349 days
View full developer profile
Detection Fingerprints

How We Detect Active Campaign & Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpop-accf/assets/admin.js/wp-content/plugins/wpop-accf/assets/admin.css

HTML / DOM Fingerprints

CSS Classes
accf7-settingsaccf7-settings-tabtab-wraptabaccf7-main-settingsgeneral-settings-sectionpro
Data Attributes
data-id
Shortcode Output
<h2><?php echo esc_html__("ActiveCampaign Setttings","wpop-accf"); ?></h2><h3><label for="accf7_enable"><input type="checkbox" name="accf7_enable" id="cf7_email_subscription" value="yes"<div class="accf7-settings-tab clearfix"><li class="tab active" data-id="general">
FAQ

Frequently Asked Questions about Active Campaign & Contact Form 7