
Agile CRM Contact Form 7 Forms Security & Risk Analysis
wordpress.org/plugins/agile-crm-contact-form-7-formsAgile CRM is an all-in-one, affordable and next-gen Customer Relationship Management (CRM) software with marketing, sales and service automation
Is Agile CRM Contact Form 7 Forms Safe to Use in 2026?
Generally Safe
Score 85/100Agile CRM Contact Form 7 Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The agile-crm-contact-form-7-forms plugin exhibits a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and avoids dangerous functions, raw SQL queries, and file operations. The use of prepared statements for SQL queries and the presence of some nonce and capability checks are good security practices. However, concerns arise from the static analysis findings, particularly the presence of an unprotected AJAX handler. This unprotected entry point represents a significant risk, as it could be exploited by unauthenticated users to interact with the plugin in unintended ways. Furthermore, the low percentage of properly escaped output is a notable weakness, increasing the risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully in the remaining unescaped outputs. The limited taint analysis showing no critical or high severity flows is encouraging, but this is offset by the unprotected AJAX handler and output escaping issues.
In conclusion, while the plugin demonstrates some commendable security practices and a clean vulnerability history, the unprotected AJAX endpoint and the widespread lack of output escaping are serious concerns that warrant immediate attention. The absence of known CVEs suggests a potentially diligent maintenance history, but this does not negate the identified risks within the current codebase. Addressing these specific issues would significantly improve the plugin's overall security.
Key Concerns
- Unprotected AJAX handler found
- Low percentage of properly escaped output
Agile CRM Contact Form 7 Forms Security Vulnerabilities
Agile CRM Contact Form 7 Forms Code Analysis
Output Escaping
Data Flow Analysis
Agile CRM Contact Form 7 Forms Attack Surface
AJAX Handlers 2
WordPress Hooks 5
Maintenance & Trust
Agile CRM Contact Form 7 Forms Maintenance & Trust
Maintenance Signals
Community Trust
Agile CRM Contact Form 7 Forms Alternatives
Agile CRM
agile-crm-lead-management
Agile CRM is an all-in-one, affordable and next-gen Customer Relationship Management (CRM) software with marketing, sales and service automation
Agile CRM Gravity Forms
agile-crm-gravity-forms
Agile CRM is an all-in-one, affordable and next-gen Customer Relationship Management (CRM) software with marketing, sales and service automation
Agile CRM Campaigns
agile-crm-campaigns
Agile CRM is an all-in-one, affordable and next-gen Customer Relationship Management (CRM) software with marketing, sales and service automation
Agile CRM Content Management
agile-crm-content-management
Agile CRM is an all-in-one, affordable and next-gen Customer Relationship Management (CRM) software with marketing, sales and service automation
Agile CRM Email Marketing
agile-crm-email-marketing
Agile CRM is an all-in-one, affordable and next-gen Customer Relationship Management (CRM) software with marketing, sales and service automation
Agile CRM Contact Form 7 Forms Developer Profile
9 plugins · 860 total installs
How We Detect Agile CRM Contact Form 7 Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/agile-crm-contact-form-7-forms/css/style.css/wp-content/plugins/agile-crm-contact-form-7-forms/js/agile-cf7-admin.js/wp-content/plugins/agile-crm-contact-form-7-forms/js/agile-cf7-frontend.jsagile-crm-contact-form-7-forms/css/style.css?ver=agile-crm-contact-form-7-forms/js/agile-cf7-admin.js?ver=agile-crm-contact-form-7-forms/js/agile-cf7-frontend.js?ver=HTML / DOM Fingerprints
agilecrm-cf7-map-fields-sectionagilecrm-cf7-account-sectionagilecrm-cf7-form-map-sectiondata-agilecrm-cf7-form-iddata-agilecrm-cf7-field-namewindow.agilecf7_admin_ajax_object/wp-json/agilecrm/v1/settings