WYSIWYG Editor for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/wysiwyg-editor-for-contact-form-7

Let's you add a WYSIWYG Editor field for Contact Form 7.

200 active installs v1.0.4 PHP 5.6+ WP 5.0+ Updated Aug 28, 2021
editorrichtexttinymcewysiwyg
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WYSIWYG Editor for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

WYSIWYG Editor for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "wysiwyg-editor-for-contact-form-7" plugin, version 1.0.4, exhibits an exceptionally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events means there are no exposed entry points that attackers could directly exploit. Furthermore, the code signals indicate a clean codebase with no dangerous functions, no direct SQL queries (all are prepared statements), and no file operations or external HTTP requests, all of which are excellent security practices. The limited number of output operations, with a high percentage properly escaped, also contributes positively to its security. The lack of any recorded vulnerabilities, critical taint flows, or unpatched CVEs further reinforces this assessment. This plugin appears to be very well-written from a security perspective, focusing on minimal functionality and robust coding practices. The primary concern, if any, would be the complete lack of any capability checks, which, while not a direct vulnerability in itself given the lack of entry points, means that if new entry points were ever introduced, they might not have proper authorization checks. However, with the current state of the plugin, this is a very minor theoretical concern.

Key Concerns

  • No capability checks found
Vulnerabilities
None known

WYSIWYG Editor for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WYSIWYG Editor for Contact Form 7 Release Timeline

v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

WYSIWYG Editor for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped8 total outputs
Attack Surface

WYSIWYG Editor for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwpcf7_admin_initincludes\modules\admin.php:44
actionadmin_noticesincludes\modules\admin.php:46
actionwpcf7_initincludes\modules\frontend.php:45
actionwp_enqueue_scriptsincludes\modules\frontend.php:59
actionplugins_loadedincludes\plugin.php:60
Maintenance & Trust

WYSIWYG Editor for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedAug 28, 2021
PHP min version5.6
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs200
Developer Profile

WYSIWYG Editor for Contact Form 7 Developer Profile

Dimitris Chatzis

3 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WYSIWYG Editor for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wysiwyg-editor-for-contact-form-7/assets/js/main.frontend.js
Script Paths
/wp-content/plugins/wysiwyg-editor-for-contact-form-7/assets/js/main.frontend.js
Version Parameters
wysiwyg-editor-for-contact-form-7/assets/js/main.frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpcf7-wysiwyg-container--has-mediaButton
Data Attributes
wysiwyg
Shortcode Output
<div class="wpcf7-wysiwyg-container<textarea name="
FAQ

Frequently Asked Questions about WYSIWYG Editor for Contact Form 7