WP Webhooks – Contact Form 7 Integration Security & Risk Analysis

wordpress.org/plugins/wpwh-contact-form-7

A WP Webhooks extension to integrate Contact Form 7

100 active installs v1.2.1 PHP + WP 4.7+ Updated May 2, 2021
automationcontactcontact-form-7ironikuswebhooks
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Webhooks – Contact Form 7 Integration Safe to Use in 2026?

Generally Safe

Score 85/100

WP Webhooks – Contact Form 7 Integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "wpwh-contact-form-7" v1.2.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of direct attack surface vectors such as AJAX handlers, REST API routes, shortcodes, and cron events is a significant positive. Furthermore, the plugin demonstrates good practice by exclusively using prepared statements for its SQL queries, mitigating the risk of SQL injection vulnerabilities. The plugin also appears to handle file operations and external HTTP requests responsibly.

However, there are notable concerns regarding output escaping, with only 8% of outputs being properly escaped. This low percentage suggests a significant risk of Cross-Site Scripting (XSS) vulnerabilities, where unsanitized data might be rendered directly in the user's browser. The absence of nonce checks and capability checks, coupled with the limited attack surface, might indicate a design where these checks are not deemed necessary by the developer, but it still represents a potential weakness if any unforeseen entry points are discovered or if the plugin's functionality evolves.

The plugin's vulnerability history is clean, with no known CVEs. This, combined with the lack of critical or high-severity taint flows, suggests that the current version is likely secure against known threats. The overall conclusion is that while the plugin avoids common pitfalls like unpatched CVEs and direct SQL injection, the poor output escaping practices present a substantial risk of XSS vulnerabilities that needs to be addressed.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

WP Webhooks – Contact Form 7 Integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Webhooks – Contact Form 7 Integration Release Timeline

v1.2.1Current
v1.2
v1.1.2
v1.1.1
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

WP Webhooks – Contact Form 7 Integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
24
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
5
External Requests
0
Bundled Libraries
0

Output Escaping

8% escaped26 total outputs
Attack Surface

WP Webhooks – Contact Form 7 Integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedwpwh-cf7.php:26
filterwpwhpro/webhooks/get_webhooks_triggerswpwh-cf7.php:27
actionadmin_noticeswpwh-cf7.php:28
actionadmin_initwpwh-cf7.php:29
actionwpcf7_mail_sentwpwh-cf7.php:314
filterironikus_demo_test_cf7_formswpwh-cf7.php:315
filterwpcf7_skip_mailwpwh-cf7.php:316
actionwpwhpro_plugin_loadedwpwh-cf7.php:724
actionadmin_noticeswpwh-cf7.php:728
Maintenance & Trust

WP Webhooks – Contact Form 7 Integration Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 2, 2021
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

WP Webhooks – Contact Form 7 Integration Developer Profile

Cozmoslabs

11 plugins · 520K total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
613 days
View full developer profile
Detection Fingerprints

How We Detect WP Webhooks – Contact Form 7 Integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpwh-contact-form-7/wpwh-cf7.php

HTML / DOM Fingerprints

Data Attributes
wpwhkey
FAQ

Frequently Asked Questions about WP Webhooks – Contact Form 7 Integration