Agile CRM Security & Risk Analysis

wordpress.org/plugins/agile-crm-lead-management

Agile CRM is an all-in-one, affordable and next-gen Customer Relationship Management (CRM) software with marketing, sales and service automation

600 active installs vv1.2 PHP + WP 3.0.1+ Updated Nov 19, 2018
agile-crmcrmcrm-plugincustomer-relationship-managementsmall-business-crm
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Agile CRM Safe to Use in 2026?

Generally Safe

Score 85/100

Agile CRM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The 'agile-crm-lead-management' vv1.2 plugin exhibits a generally good security posture based on the provided static analysis. The absence of critical or high-severity taint flows, raw SQL queries, and the presence of nonce and capability checks on the identified entry points are positive indicators. Furthermore, the plugin has no recorded vulnerability history, suggesting a responsible development approach or a lack of discovered issues.

However, a notable concern is the relatively low percentage of properly escaped output (58%). This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, particularly if user-supplied data is displayed without sufficient sanitization. While the static analysis found no critical issues here, it's a common entry point for attacks. The presence of unsanitized paths in the taint analysis, although not classified as critical or high, also warrants attention as these could potentially lead to security problems if exploited.

In conclusion, the plugin demonstrates strengths in core security practices like prepared SQL statements and the use of checks on its entry points. The lack of historical vulnerabilities is also a positive sign. The primary weakness lies in the insufficient output escaping, which requires immediate attention. Addressing this, along with a closer examination of the unsanitized paths, would significantly improve the plugin's overall security.

Key Concerns

  • Insufficient output escaping detected
  • Unsanitized paths found in taint analysis
Vulnerabilities
None known

Agile CRM Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Agile CRM Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
55
75 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

58% escaped130 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

5 flows2 with unsanitized paths
agilecrm_settings_page (index.php:833)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Agile CRM Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[agileform] index.php:1132
WordPress Hooks 17
actionwp_enqueue_stylesindex.php:29
actionwpindex.php:36
actioninitindex.php:53
actionadmin_menuindex.php:81
actionload-post.phpindex.php:1000
actionload-post-new.phpindex.php:1001
actionsave_postindex.php:1002
actionadd_meta_boxesindex.php:1005
actionadmin_headindex.php:1105
filtermce_external_pluginsindex.php:1117
filtermce_buttonsindex.php:1118
actionadmin_enqueue_scriptsindex.php:1205
actionwp_footerindex.php:1262
actionwp_enqueue_scriptsindex.php:1269
actionadmin_enqueue_scriptsindex.php:1273
actionadmin_enqueue_scriptsindex.php:1279
actionadmin_enqueue_scriptsindex.php:1284
Maintenance & Trust

Agile CRM Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedNov 19, 2018
PHP min version
Downloads34K

Community Trust

Rating52/100
Number of ratings5
Active installs600
Developer Profile

Agile CRM Developer Profile

Agile CRM

9 plugins · 860 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Agile CRM

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/agile-crm-lead-management/css/style.css

HTML / DOM Fingerprints

CSS Classes
textaligncenterlabel-success
Data Attributes
title
JS Globals
agilecrm_hidedata_js
REST Endpoints
/wp-json/agilecrm-lead-management/
FAQ

Frequently Asked Questions about Agile CRM