WPOP Contact Form 7 to Hubspot Security & Risk Analysis

wordpress.org/plugins/wpop-contactform-hubspot

Add Contact Form 7 Data to Hubspot Contact lists.

200 active installs v1.0.9 PHP 5.6+ WP 4.5.0+ Updated Sep 16, 2022
contact-form-7contact-form-7-hubspothubspothubspot-formhubspot-forms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPOP Contact Form 7 to Hubspot Safe to Use in 2026?

Generally Safe

Score 85/100

WPOP Contact Form 7 to Hubspot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The wpop-contactform-hubspot plugin v1.0.9 exhibits a generally strong security posture based on the static analysis provided. The absence of any identified attack surface entry points, dangerous functions, raw SQL queries, or taint flows is a significant positive indicator. This suggests the developers have implemented robust input validation and secure coding practices, which is commendable.

However, a key concern arises from the low percentage of properly escaped output (55%). This leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks, where malicious scripts could be injected and executed within the WordPress admin or frontend if user-supplied data is not sanitized before being displayed. Additionally, the complete lack of nonce checks and capability checks, combined with zero uncovered AJAX handlers or REST API routes, might indicate a very limited feature set, or it could be an oversight that leaves potential future entry points exposed without essential security layers. The plugin's history of zero known vulnerabilities further reinforces a perception of good development, but the static analysis points to a specific area requiring immediate attention to mitigate potential XSS risks.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

WPOP Contact Form 7 to Hubspot Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WPOP Contact Form 7 to Hubspot Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
36
44 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

55% escaped80 total outputs
Attack Surface

WPOP Contact Form 7 to Hubspot Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterwpcf7_editor_panelsincludes\hbcf7-settings.php:7
actionsave_post_wpcf7_contact_formincludes\hbcf7-settings.php:8
actionwpcf7_before_send_mailincludes\hbcf7-subscribe.php:7
actioninitwpop-contactform-hubspot.php:24
actionadmin_enqueue_scriptswpop-contactform-hubspot.php:25
actioninitwpop-contactform-hubspot.php:26
actionadmin_noticeswpop-contactform-hubspot.php:37
Maintenance & Trust

WPOP Contact Form 7 to Hubspot Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedSep 16, 2022
PHP min version5.6
Downloads5K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

WPOP Contact Form 7 to Hubspot Developer Profile

wpoperations

9 plugins · 17K total installs

70
trust score
Avg Security Score
87/100
Avg Patch Time
349 days
View full developer profile
Detection Fingerprints

How We Detect WPOP Contact Form 7 to Hubspot

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpop-contactform-hubspot/assets/admin.js/wp-content/plugins/wpop-contactform-hubspot/assets/admin.css
Script Paths
/wp-content/plugins/wpop-contactform-hubspot/assets/admin.js
Version Parameters
wpop-contactform-hubspot/assets/admin.js?ver=wpop-contactform-hubspot/assets/admin.css

HTML / DOM Fingerprints

CSS Classes
hbcf7-settingshbcf7-settings-tabtab-wraptabhbcf7-main-settingsgeneral-settings-section
Data Attributes
data-id="general"data-id="form-fields"data-id="form-pro"
FAQ

Frequently Asked Questions about WPOP Contact Form 7 to Hubspot