Agile CRM Landing Pages Security & Risk Analysis

wordpress.org/plugins/agile-crm-landing-pages

Agile CRM is an all-in-one, affordable and next-gen Customer Relationship Management (CRM) software with marketing, sales and service automation

10 active installs v1.0 PHP + WP 3.0.1+ Updated Dec 28, 2017
agile-crmcrmcrm-plugincustomer-relationship-managementsmall-business-crm
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Agile CRM Landing Pages Safe to Use in 2026?

Generally Safe

Score 85/100

Agile CRM Landing Pages has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The "agile-crm-landing-pages" v1.0 plugin exhibits a generally good security posture, with no identified critical or high severity vulnerabilities in its historical record or static analysis. The complete absence of known CVEs and the use of prepared statements for all SQL queries are strong indicators of a development team prioritizing security. Furthermore, the plugin has a limited attack surface, with only one shortcode identified and no AJAX handlers or REST API routes found in the analysis, reducing potential entry points for attackers. The presence of nonce and capability checks, though limited, suggests an awareness of WordPress security best practices.

However, there are areas for improvement. The output escaping is only properly implemented in 58% of cases, which presents a moderate risk of Cross-Site Scripting (XSS) vulnerabilities. While taint analysis did not reveal any unsanitized paths, the partially unescaped output could be exploited if an attacker can control the data being outputted. The plugin also makes 13 external HTTP requests, which, while not inherently a vulnerability, can be a vector for supply chain attacks if the external services are compromised or if the requests are not handled securely. The limited number of capability checks and nonce checks also indicate that some entry points might not be sufficiently protected against unauthorized access or malicious manipulation.

In conclusion, the "agile-crm-landing-pages" v1.0 plugin is relatively secure due to its lack of known vulnerabilities and sound SQL handling. The absence of critical flaws in static and taint analysis is reassuring. Nevertheless, the unescaped output is a notable weakness that requires attention to mitigate XSS risks. The plugin should consider strengthening its authorization checks and ensuring all output is properly sanitized to further enhance its security.

Key Concerns

  • Output escaping is only 58% properly escaped
  • Limited nonce checks (4 total)
  • Limited capability checks (2 total)
Vulnerabilities
None known

Agile CRM Landing Pages Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Agile CRM Landing Pages Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Agile CRM Landing Pages Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
55
75 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
13
Bundled Libraries
0

Output Escaping

58% escaped130 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

5 flows
agilecrm_landing_pages_dashboard_page (index.php:136)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Agile CRM Landing Pages Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[agileform_landing_pages] index.php:1226
WordPress Hooks 17
actionwp_enqueue_stylesindex.php:28
actionwpindex.php:35
actioninitindex.php:52
actionadmin_menuindex.php:93
actionload-post.phpindex.php:1081
actionload-post-new.phpindex.php:1082
actionsave_postindex.php:1083
actionadd_meta_boxesindex.php:1086
actionadmin_headindex.php:1199
filtermce_external_pluginsindex.php:1211
filtermce_buttonsindex.php:1212
actionadmin_enqueue_scriptsindex.php:1312
actionwp_footerindex.php:1382
actionwp_enqueue_scriptsindex.php:1389
actionadmin_enqueue_scriptsindex.php:1393
actionadmin_enqueue_scriptsindex.php:1399
actionadmin_enqueue_scriptsindex.php:1404
Maintenance & Trust

Agile CRM Landing Pages Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.33
Last updatedDec 28, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Agile CRM Landing Pages Developer Profile

Agile CRM

10 plugins · 870 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Agile CRM Landing Pages

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/agile-crm-landing-pages/css/style.css

HTML / DOM Fingerprints

CSS Classes
agilewrapperagilewrapper2label-success
Data Attributes
id="agilewrapper"class="textaligncenter"title='Agile Crm logo'id="agilewrapper2"
REST Endpoints
/dev/api/forms
FAQ

Frequently Asked Questions about Agile CRM Landing Pages