Zibal Payment Gateway for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/zibal-payment-gateway-for-contact-form7

با نصب این پلاگین می توانید از خدمات درگاه پرداخت زیبال برروی افزونه فرم تماس ۷ استفاده کنید!

40 active installs v1.0 PHP 7.0+ WP 4.5+ Updated Jun 20, 2022
contact-form-7gatewaypaymentzibal%d8%b2%db%8c%d8%a8%d8%a7%d9%84
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zibal Payment Gateway for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

Zibal Payment Gateway for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "zibal-payment-gateway-for-contact-form7" plugin version 1.0 exhibits a generally positive security posture with no known vulnerabilities or critical security flaws detected in the static analysis. The plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and performs a reasonable amount of output escaping, with 64% of outputs being properly handled. It also correctly limits its attack surface to a single shortcode and has limited capability checks for its entry points.

However, there are a few areas of concern. The presence of one taint flow with an unsanitized path, rated as high severity, is a significant risk that could potentially lead to vulnerabilities if exploited. While there are no external HTTP requests or file operations flagged, and no dangerous functions are used, the lack of any nonce checks across all entry points is a notable weakness. This could make certain operations susceptible to Cross-Site Request Forgery (CSRF) attacks, especially if the shortcode or any implicit actions it triggers are sensitive.

In conclusion, the plugin's strength lies in its responsible handling of database interactions and lack of historical vulnerabilities. The main weaknesses are the high-severity unsanitized taint flow and the absence of nonce checks. Addressing these specific issues would significantly improve the plugin's overall security. The plugin's limited entry points and controlled code execution pathways are positive factors, but the identified taint flow and lack of CSRF protection warrant attention.

Key Concerns

  • High severity unsanitized taint flow
  • 0 Nonce checks on entry points
  • 36% of outputs not properly escaped
Vulnerabilities
None known

Zibal Payment Gateway for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Zibal Payment Gateway for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
14 prepared
Unescaped Output
12
21 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared14 total queries

Output Escaping

64% escaped33 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
zgcf7_cf7pp_admin_table (gateway_func.php:539)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Zibal Payment Gateway for Contact Form 7 Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[result_payment] gateway_func.php:142
WordPress Hooks 8
actionadmin_noticesgateway_func.php:248
actionadmin_menugateway_func.php:264
actionwpcf7_before_send_mailgateway_func.php:283
actionwpcf7_mail_sentgateway_func.php:290
actionwpcf7_admin_after_additional_settingsgateway_func.php:316
filterwpcf7_editor_panelsgateway_func.php:333
actionwpcf7_save_contact_formgateway_func.php:409
actionadmin_noticesgateway_func.php:730
Maintenance & Trust

Zibal Payment Gateway for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedJun 20, 2022
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Alternatives

Zibal Payment Gateway for Contact Form 7 Alternatives

Developer Profile

Zibal Payment Gateway for Contact Form 7 Developer Profile

Mohammad Zamanzadeh

5 plugins · 7K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zibal Payment Gateway for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zibal-payment-gateway-for-contact-form7/style.css
Version Parameters
zibal-payment-gateway-for-contact-form7/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
vipbodymrbox2
Data Attributes
data-cf7pp-merchantdata-cf7pp-amountdata-cf7pp-descriptiondata-cf7pp-namedata-cf7pp-emaildata-cf7pp-phone+1 more
JS Globals
window.ZibalCF7
Shortcode Output
<div style="border:#CCC 1px solid; width:90%;"><div class="mrbox2"><h3><span><html><head>
FAQ

Frequently Asked Questions about Zibal Payment Gateway for Contact Form 7