shouldiuse.io

Categories

VERDICT

Should I use Contact Form 7?

Free WordPress contact form plugin - contactform7.com

Depends. Buy it if you run WordPress and want a free, no-frills contact form and are comfortable with shortcodes and add-ons. Skip it if you want drag-and-drop building, saved entries, or a polished experience out of the box.

Confidence

Medium. Based on 20+ public sources including official docs, Reddit threads, reviews, and security databases

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

Core plugin

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Third-party add-onsVaries

Best for

  • WordPress sites needing a basic contact form
  • Budget-free or zero-cost projects
  • Developers comfortable with shortcodes
  • Simple lead capture on small sites

Not for

  • Non-technical users wanting drag-and-drop builders
  • Anyone needing entries saved and searchable out of the box
  • Teams wanting multi-step, payment, or survey forms without add-ons
  • Sites with low tolerance for plugin security patching

Gotchas - check before you buy

high

Popular companion plugin Redirection for CF7 had high-severity vulnerabilities

medium

Guess: submissions aren't saved by default; Flamingo companion plugin required

medium

Email failures often force buying or adding an SMTP plugin

medium

Free core means stitching together paid third-party add-ons for real features

Pros and cons

Pros

  • Free and open source core with unlimited forms
  • Huge install base of 5M+ active sites
  • Actively released; latest version 6.1.6
  • Built-in spam filtering via Akismet and reCAPTCHA
  • Deeply loyal users; many refuse to switch

Cons

  • Core is barebones; storage and redirects require companion plugins
  • Users report it can slow down websites
  • Email delivery problems are a common complaint
  • Recurring vulnerabilities across versions and companion plugins
  • Users question the pace of meaningful maintenance

Sources & method

Analyzed 9/29/2026 - 12 sources - Mixed record: actively patched, but a steady CVE history including a 2020 flaw affecting 5M sites and recent reported RCE issues.

official x3review x6security x2news x1
  • CVE-2025-14842 — Contact Form 7 RCE, Listed in SentinelOne's vulnerability database as a remote code execution issue.
  • CVE-2025-8289 — Redirection for Contact Form 7 RCE, Companion plugin RCE listed by SentinelOne.
  • Reflected XSS in Contact Form 7 <= 5.9, Reflected cross-site scripting patched in 2024.
  • 2020 file-upload flaw, Security Affairs reported 5 million sites potentially impacted.

Key stats

  • Value for money: 5/5

    Rating

  • Free

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 5/5. Core is free and unlimited; add-ons optional
  • Ease of use: 2/5. Shortcode-based setup; beginners report struggles
  • Feature depth: 2/5. Barebones core; storage and redirects need add-ons
  • Support quality: 2/5. Community forums only; users question maintenance pace
  • Security posture: 2/5. Recurring CVEs, including reported RCE issues
  • 5M+ Active installs One of WordPress's most-installed plugins
  • Free Core plugin price Open source, no official paid tier
  • 52 G2 reviews Across Contact Form 7 products
  • 8 Wordfence-listed vulnerabilities Plus companion-plugin CVEs

Pricing

Core plugin

Free

  • Unlimited contact forms
  • Akismet/reCAPTCHA spam filtering
  • Community support only

Third-party add-ons

Varies

  • Entry storage, redirects, drag-and-drop
  • Sold by other vendors, not Contact Form 7

Security

Mixed record: actively patched, but a steady CVE history including a 2020 flaw affecting 5M sites and recent reported RCE issues.

  • CVE-2025-14842 — Contact Form 7 RCEListed in SentinelOne's vulnerability database as a remote code execution issue.10
  • CVE-2025-8289 — Redirection for Contact Form 7 RCECompanion plugin RCE listed by SentinelOne.
  • Reflected XSS in Contact Form 7 <= 5.9Reflected cross-site scripting patched in 2024.
  • 2020 file-upload flawSecurity Affairs reported 5 million sites potentially impacted.11
Full analysis

Based on 20+ public sources including official docs, Reddit threads, reviews, and security databases

Free, battle-tested WordPress contact form — great for basics, dated UX, everything else costs add-ons.

Methodology

Based on 20+ public sources including official docs, Reddit threads, reviews, and security databases

Sources

  1. official
  2. official
  3. official
  4. review
  5. review
  6. review
  7. review
  8. review
  9. security
  10. security
  11. news
  12. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.