PLUGIN SECURITY
Is Flamingo safe?
A trustworthy message storage plugin for Contact Form 7.
What this plugin does
- Slug:
flamingo - Author: Rock Lobster Inc.
- 800000+ active installs
- 84/100 rating (121 reviews on wordpress.org)
- 9407051 all-time downloads
- On WordPress.org since 2012-05-05
birdcontactcrmmail
Maintenance status
- Latest known version: 2.6.3
- Last updated: 2026-08-18 9:20am GMT
- Tested up to WordPress: 7.1
- Requires PHP: 7.4+
- Max supported PHP (analyzed): 8.4
Known vulnerabilities
0 known CVEs on file for Flamingo. Reported between 2020 and 2020.
| CVE | Vulnerability | Type | Severity | Affected | Fixed in | Published | Status |
|---|---|---|---|---|---|---|---|
| — | Flamingo [flamingo] < 2.1.1 | — | Unknown | < 2.1.1 | 2.1.1 | 2020-01-28 | ✓ fixed in latest |
| — | Flamingo [flamingo] < 2.1.1 | — | Unknown | < 2.1.1 | 2.1.1 | 2020-01-15 | ✓ fixed in latest |
| — | Flamingo [flamingo] < 2.1.1 | — | Unknown | < 2.1.1 | 2.1.1 | — | ✓ fixed in latest |
| — | Flamingo < 2.1.1 - CSV Injection | — | Unknown | < 2.1.1 | 2.1.1 | — | ✓ fixed in latest |
How to fix it
Keep Flamingo updated — 2.6.3 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
- Contact Form 7 add confirm — 50000+ active installs — 100/100 (4) — max PHP 8.4
- WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress — 10000+ active installs — 100/100 (2) — max PHP 8.4
- Sticky Side Buttons — 10000+ active installs — 90/100 (40) — max PHP 8.4
- Rich Contact Widget — 9000+ active installs — 92/100 (7)
- Contact Form Email — 8000+ active installs — 86/100 (102)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.