WPshore Contact Form 7 Spam Prevention Security & Risk Analysis

wordpress.org/plugins/wpshore-contact-form-7-spam-prevention

WPshore Contact Form 7 Spam Prevention helps you manage your Inbox to keep it free of unwanted e-mail messages.

10 active installs v1.0 PHP + WP 3.3+ Updated Jan 21, 2025
antispamlimit-spamspamspam-preventionwpshore-contact-form-7
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WPshore Contact Form 7 Spam Prevention Safe to Use in 2026?

Generally Safe

Score 92/100

WPshore Contact Form 7 Spam Prevention has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "wpshore-contact-form-7-spam-prevention" version 1.0 exhibits a strong security posture based on the static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events that could serve as entry points, and consequently, no unprotected entry points were detected. The code also demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and not making external HTTP requests. This suggests a well-developed and securely coded plugin with a minimal attack surface.

However, the analysis does reveal some areas for improvement. Specifically, only 50% of output operations are properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is outputted without sufficient sanitization. The absence of any nonce checks or capability checks is also a concern, as these are fundamental security mechanisms in WordPress to prevent unauthorized actions and token hijacking. While the vulnerability history is clean, the lack of these checks means that any future vulnerabilities or complexities introduced into the code could be more impactful.

In conclusion, the plugin has a solid foundation with no immediate critical flaws detected in the provided data. Its strengths lie in its minimal attack surface and secure data handling for SQL. The primary weaknesses are related to output escaping and the complete absence of authorization checks, which are essential for a robust security strategy. Addressing these areas would significantly strengthen the plugin's overall security.

Key Concerns

  • Unescaped output present
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

WPshore Contact Form 7 Spam Prevention Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

WPshore Contact Form 7 Spam Prevention Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped4 total outputs
Attack Surface

WPshore Contact Form 7 Spam Prevention Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuspam_prevention.php:10
actionplugins_loadedspam_prevention.php:36
actionadmin_noticesspam_prevention.php:46
filterwpcf7_spamspam_prevention.php:81
Maintenance & Trust

WPshore Contact Form 7 Spam Prevention Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedJan 21, 2025
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

WPshore Contact Form 7 Spam Prevention Developer Profile

nablasol

4 plugins · 1K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WPshore Contact Form 7 Spam Prevention

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpshore-contact-form-7-spam-prevention/cf7_spam_prevention/limit.png

HTML / DOM Fingerprints

Data Attributes
data-allowedurl
Shortcode Output
[preventspamurl allowedurl value:
FAQ

Frequently Asked Questions about WPshore Contact Form 7 Spam Prevention