
Active Campaign & Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/wpop-accfAdd Contact Form 7 Data to ActiveCampaign Contact lists.
Is Active Campaign & Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100Active Campaign & Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wpop-accf" v1.2.3 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events suggests a limited attack surface. Furthermore, the complete utilization of prepared statements for SQL queries and the lack of identified dangerous functions are significant strengths. The absence of any recorded vulnerabilities or CVEs in its history also contributes positively to its security profile.
However, there are areas of concern that warrant attention. The fact that only 30% of output is properly escaped indicates a substantial risk of cross-site scripting (XSS) vulnerabilities. This is particularly concerning given the lack of explicit capability checks and nonce checks on potential entry points, although the static analysis reports zero entry points. The single external HTTP request, while not inherently a vulnerability, should be carefully scrutinized to ensure it is not exploitable. The lack of any taint analysis findings could be due to the limited scope of the analysis or the plugin's actual design, but combined with the unescaped output, it presents a potential blind spot.
In conclusion, while the plugin demonstrates good practices in areas like SQL query handling and has a clean vulnerability history, the significant percentage of unescaped output presents a notable risk. The absence of identified entry points and vulnerabilities is a positive sign, but the unescaped output remains the most pressing concern from the provided data. Further manual code review of the output handling mechanisms and the external HTTP request would be prudent.
Key Concerns
- Low percentage of properly escaped output
- No capability checks on potential entry points
- No nonce checks on potential entry points
- External HTTP request without specific analysis
Active Campaign & Contact Form 7 Security Vulnerabilities
Active Campaign & Contact Form 7 Code Analysis
Output Escaping
Active Campaign & Contact Form 7 Attack Surface
WordPress Hooks 7
Maintenance & Trust
Active Campaign & Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Active Campaign & Contact Form 7 Alternatives
CWW connector Lite – Connect Contact Form 7 & ActiveCampaign
cww-connector-lite
CWW Connector Lite is an addon for contact form 7 which allows you to collect leads from contact form 7 to ActiveCampaign.
Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-active-campaign
Send Contact Form 7, WPForms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to ActiveCampaign.
ActiveCampaign Newsletter Subscription
activecampaign-newsletter-subscription
This is Newsletter Subscription Plugin, Which is used to add users to Selected ActiveCampaign List.
Fast ActiveCampaign
fast-activecampaign
Easily Sync ActiveCampaign Contacts With Your WordPress Users. Direct user tagging integration through the Fast Flow Dashboard.
Data Sync with ActiveCampaign for WooCommerce
data-sync-for-woocommerce-with-activecampaign
WooCommerce data synchronization with ActiveCampaign
Active Campaign & Contact Form 7 Developer Profile
9 plugins · 17K total installs
How We Detect Active Campaign & Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wpop-accf/assets/admin.js/wp-content/plugins/wpop-accf/assets/admin.cssHTML / DOM Fingerprints
accf7-settingsaccf7-settings-tabtab-wraptabaccf7-main-settingsgeneral-settings-sectionprodata-id<h2><?php echo esc_html__("ActiveCampaign Setttings","wpop-accf"); ?></h2><h3><label for="accf7_enable"><input type="checkbox" name="accf7_enable" id="cf7_email_subscription" value="yes"<div class="accf7-settings-tab clearfix"><li class="tab active" data-id="general">