Agile CRM Forms Security & Risk Analysis

wordpress.org/plugins/agile-crm-forms

Agile CRM is an all-in-one, affordable and next-gen Customer Relationship Management (CRM) software with marketing, sales and service automation

10 active installs v1.0 PHP + WP 3.0.1+ Updated Unknown
agile-crmcrmcrm-plugincustomer-relationship-managementsmall-business-crm
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Agile CRM Forms Safe to Use in 2026?

Generally Safe

Score 100/100

Agile CRM Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The agile-crm-forms plugin v1.0 exhibits a generally strong security posture based on the provided static analysis. There are no identified dangerous functions, all SQL queries are prepared, and the absence of known vulnerabilities in its history suggests a history of secure development. The plugin also demonstrates good practices by implementing nonce and capability checks, albeit limited in number.

However, a significant concern is the relatively low percentage of properly escaped output (58%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, as unsanitized output can be manipulated by attackers to inject malicious scripts. While the attack surface is small and there are no unprotected entry points, the lack of comprehensive output sanitization is a notable weakness. The presence of external HTTP requests also warrants attention, as insecure handling of these could lead to various security issues if not properly validated or sanitized.

In conclusion, while the plugin has a good foundation with secure SQL handling and a clean vulnerability history, the high rate of unescaped output is a critical area for improvement. Addressing this could significantly enhance the plugin's security and mitigate the risk of XSS attacks. The limited number of checks also suggests that more robust security measures could be implemented.

Key Concerns

  • Low percentage of properly escaped output
  • Limited number of capability checks
  • Limited number of nonce checks
Vulnerabilities
None known

Agile CRM Forms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Agile CRM Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
55
75 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
13
Bundled Libraries
0

Output Escaping

58% escaped130 total outputs
Data Flows
All sanitized

Data Flow Analysis

5 flows
agilecrm_forms_dashboard_page (index.php:136)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Agile CRM Forms Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[agileform_forms] index.php:1226
WordPress Hooks 17
actionwp_enqueue_stylesindex.php:28
actionwpindex.php:35
actioninitindex.php:52
actionadmin_menuindex.php:93
actionload-post.phpindex.php:1081
actionload-post-new.phpindex.php:1082
actionsave_postindex.php:1083
actionadd_meta_boxesindex.php:1086
actionadmin_headindex.php:1199
filtermce_external_pluginsindex.php:1211
filtermce_buttonsindex.php:1212
actionadmin_enqueue_scriptsindex.php:1312
actionwp_footerindex.php:1382
actionwp_enqueue_scriptsindex.php:1389
actionadmin_enqueue_scriptsindex.php:1393
actionadmin_enqueue_scriptsindex.php:1399
actionadmin_enqueue_scriptsindex.php:1404
Maintenance & Trust

Agile CRM Forms Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Agile CRM Forms Developer Profile

Agile CRM

9 plugins · 860 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Agile CRM Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/agile-crm-forms/css/style.css

HTML / DOM Fingerprints

CSS Classes
agilewrappertextaligncenteragilewrapper2
Data Attributes
title='Agile Crm logo'
REST Endpoints
/dev/api/forms
FAQ

Frequently Asked Questions about Agile CRM Forms