
Auto Quote Security & Risk Analysis
wordpress.org/plugins/auto-quoteThe Auto Quote plugin enables your website to automatically collect leads for your products and services.
Is Auto Quote Safe to Use in 2026?
Generally Safe
Score 85/100Auto Quote has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "auto-quote" plugin v1.5.2 exhibits a mixed security posture. On the positive side, it has a very small attack surface with only one entry point (a shortcode) and no known historical vulnerabilities. Furthermore, all SQL queries are properly prepared, and there are a reasonable number of nonce and capability checks present. However, the presence of two instances of the dangerous `unserialize` function is a significant concern, especially without further context on how the serialized data is sourced and validated.
The static analysis reveals potential risks primarily associated with the `unserialize` function. While the taint analysis did not identify critical or high severity flows, the fact that all four analyzed flows had unsanitized paths, even if classified as lower severity, warrants attention. The output escaping, with only 42% being properly escaped, also presents a moderate risk of cross-site scripting (XSS) vulnerabilities, particularly if the unescaped outputs handle user-controlled data.
Given the absence of any recorded vulnerabilities, the plugin's history is a strength, suggesting a history of responsible development or limited exposure to exploitable issues. However, this does not negate the risks identified in the current code. The plugin's strengths lie in its limited attack surface and secure SQL handling. The primary weaknesses are the use of `unserialize` and the concerning percentage of unescaped output, which could be exploited in conjunction with other less severe issues.
Key Concerns
- Use of unserialize function
- Low percentage of properly escaped output
- All analyzed taint flows have unsanitized paths
Auto Quote Security Vulnerabilities
Auto Quote Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Auto Quote Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Auto Quote Maintenance & Trust
Maintenance Signals
Community Trust
Auto Quote Alternatives
Outfunnel: Web Visitor Tracking & CRM Integration
outfunnel
Easily sync leads from various Wordpress forms to Pipedrive, Copper, HubSpot and other CRMs. Includes web visitor tracking.
Logic Hop HubSpot Add-on
logic-hop-hubspot-add-on
The Logic Hop HubSpot Add-on brings the power of personalization to WordPress with HubSpot.
AFI – The Easiest Integration Plugin
advanced-form-integration
Connect any WordPress form or event to 200+ apps — no code. Send leads, orders, and signups to your CRM, email, or sheets in minutes.
WP Gravity Forms Salesforce
gf-salesforce-crmperks
Gravity Forms Salesforce Add-on sends Gravity forms entries to salesforce CRM.
Object Sync for Salesforce
object-sync-for-salesforce
Object Sync for Salesforce maps and syncs data between Salesforce objects and WordPress objects.
Auto Quote Developer Profile
1 plugin · 20 total installs
How We Detect Auto Quote
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/auto-quote/css/form.css/wp-content/plugins/auto-quote/js/jquery.cbchecker.js/wp-content/plugins/auto-quote/js/jquery.cbchecker.jsHTML / DOM Fingerprints
aq-fieldaq-buttonname="quote-requested"id="checkBtn"name="firstname"name="lastname"name="email"name="phone"+1 more<form action="" method="post"><p>First Name<br/>