
Apptivo Business Site Security & Risk Analysis
wordpress.org/plugins/apptivo-business-siteCreate contact forms, newsletter signups, and customer testimonials, integrated with Apptivo.
Is Apptivo Business Site Safe to Use in 2026?
Mostly Safe
Score 77/100Apptivo Business Site is generally safe to use. 3 past CVEs were resolved.
The "apptivo-business-site" plugin version 5.4 exhibits a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices regarding SQL queries and output escaping, with 100% of both using prepared statements and proper escaping, respectively. The plugin also incorporates a healthy number of nonce and capability checks. However, a significant concern arises from the presence of two AJAX handlers that lack authentication checks, creating a direct attack vector. Additionally, the taint analysis reveals that 11 out of 22 analyzed flows involve unsanitized paths, indicating a potential for vulnerabilities if these paths are exposed to user input without proper sanitization, even though no critical or high severity issues were identified in this analysis. The plugin's vulnerability history is also a major red flag, with three medium-severity CVEs, including one that remains unpatched. The types of historical vulnerabilities (Missing Authorization, CSRF, XSS) align with the identified risks in the code analysis, suggesting a pattern of insecure handling of user input and access control.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Unpatched CVEs
- Medium severity CVE history
Apptivo Business Site Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Apptivo Business Site CRM <= 5.3 - Missing Authorization to Arbitrary Content Deletion
Apptivo Business Site CRM <= 5.3 - Cross-Site Request Forgery to IP Address Block
Apptivo Business Site CRM <= 3.0.12 - Authenticated (Admin+) Stored Cross-Site Scripting
Apptivo Business Site Release Timeline
Apptivo Business Site Code Analysis
Output Escaping
Data Flow Analysis
Apptivo Business Site Attack Surface
AJAX Handlers 4
WordPress Hooks 32
Maintenance & Trust
Apptivo Business Site Maintenance & Trust
Maintenance Signals
Community Trust
Apptivo Business Site Alternatives
Lead Sync – WPForms to Jetpack CRM
sync-wpforms-jetcrm
Seamlessly sync WPForms submissions to Jetpack CRM. Automate lead capture with smart field mapping, retry logic, and per-form controls.
Juridic-OS Connector
juridic-os-connector
El plugin oficial de Juridic-OS para integración de formularios de contacto con sistemas de gestión legal.
Flamingo
flamingo
A trustworthy message storage plugin for Contact Form 7.
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
Apptivo Business Site Developer Profile
3 plugins · 50 total installs
How We Detect Apptivo Business Site
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/apptivo-business-site/assets/css/apptivo-business.css/wp-content/plugins/apptivo-business-site/assets/js/apptivo-business-plugin.js/wp-content/plugins/apptivo-business-site/assets/js/editor_plugin.jsassets/js/editor_plugin.jsassets/js/apptivo-business-plugin.jsapptivo-business-site/assets/css/apptivo-business.css?ver=apptivo-business-site/assets/js/apptivo-business-plugin.js?ver=HTML / DOM Fingerprints
apptivo-business-plugin-wrapapptivo-contentdata-apptivo-iddata-apptivo-typeAWP_PLUGIN_BASEURL[apptivo_testimonials][apptivo_jobs][apptivo_contactform][apptivo_newsletter]