Beacon Lead Magnets and Lead Capture Security & Risk Analysis

wordpress.org/plugins/beacon-by

Automatically convert blog posts into a beautiful marketing eBook in less than 2 minutes.

500 active installs v1.5.9 PHP 7.4+ WP 5.3+ Updated Dec 16, 2025
ebooklead-capturelead-capture-formlead-capture-pluginprotected-content
98
A · Safe
CVEs total2
Unpatched0
Last CVEMay 7, 2025
Safety Verdict

Is Beacon Lead Magnets and Lead Capture Safe to Use in 2026?

Generally Safe

Score 98/100

Beacon Lead Magnets and Lead Capture has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: May 7, 2025Updated 3mo ago
Risk Assessment

The 'beacon-by' plugin version 1.5.9 exhibits a mixed security posture. While it demonstrates strong adherence to secure coding practices in many areas, such as using prepared statements for all SQL queries and properly escaping the vast majority of its output, there are significant concerns that elevate its risk profile. The presence of an unprotected AJAX handler is a critical vulnerability, as it represents a direct entry point into the plugin's functionality that can be exploited without authentication. This, combined with the historical trend of Cross-Site Request Forgery (CSRF) and Cross-Site Scripting (XSS) vulnerabilities, suggests a recurring pattern of input validation and authorization weaknesses that have not been fully addressed.

The static analysis reveals one AJAX handler without authentication, which is a serious security flaw. Although the taint analysis did not flag critical or high-severity issues with unsanitized paths, the unprotected AJAX handler itself is a significant risk. The vulnerability history, featuring two medium-severity CVEs for CSRF and XSS, further reinforces the concern that user input handling and authorization mechanisms may be susceptible to manipulation. Despite the positive indicators like high output escaping and nonce checks, the single unprotected entry point and historical vulnerabilities indicate that this plugin requires careful scrutiny and likely further patching to mitigate potential risks.

In conclusion, while the 'beacon-by' plugin has strengths in its SQL query handling and output escaping, the unprotected AJAX handler and past vulnerabilities are significant weaknesses. The plugin is not entirely secure due to these identified issues, and users should be aware of the potential for exploitation, particularly if further unpatched vulnerabilities are discovered. The plugin's overall security is compromised by these specific entry points and historical patterns.

Key Concerns

  • Unprotected AJAX handler found
  • History of medium severity vulnerabilities (CSRF, XSS)
Vulnerabilities
2

Beacon Lead Magnets and Lead Capture Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-47596medium · 4.3Cross-Site Request Forgery (CSRF)

Beacon Lead Magnets and Lead Capture <= 1.5.8 - Cross-Site Request Forgery

May 7, 2025 Patched in 1.5.9 (227d)
CVE-2025-24637medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Beacon Lead Magnets and Lead Capture <= 1.5.7 - Reflected Cross-Site Scripting

Jan 6, 2025 Patched in 1.5.8 (107d)
Code Analysis
Analyzed Mar 16, 2026

Beacon Lead Magnets and Lead Capture Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
85 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped88 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

3 flows1 with unsanitized paths
router (classes\class.beacon_plugin.php:195)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Beacon Lead Magnets and Lead Capture Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_BN_get_postsbeacon-by.php:47
WordPress Hooks 3
actionadmin_initbeacon-by.php:45
actionadmin_menubeacon-by.php:46
filterplugin_row_metabeacon-by.php:49
Maintenance & Trust

Beacon Lead Magnets and Lead Capture Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 16, 2025
PHP min version7.4
Downloads63K

Community Trust

Rating88/100
Number of ratings28
Active installs500
Developer Profile

Beacon Lead Magnets and Lead Capture Developer Profile

Syed Balkhi

94 plugins · 23.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
795 days
View full developer profile
Detection Fingerprints

How We Detect Beacon Lead Magnets and Lead Capture

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/beacon-by/css/beacon.css/wp-content/plugins/beacon-by/css/font-awesome.min.css/wp-content/plugins/beacon-by/js/beacon.js
Script Paths
/wp-content/plugins/beacon-by/js/beacon.js
Version Parameters
beaconby_adminbeaconby_fontawesome

HTML / DOM Fingerprints

CSS Classes
beacon-by
HTML Comments
copyright 2016-2025 beacon.by
Data Attributes
data-beacon-by
JS Globals
Beacon_plugin
REST Endpoints
/wp-json/beacon/v1/posts
FAQ

Frequently Asked Questions about Beacon Lead Magnets and Lead Capture