Centous Integration for Contact Form 7 and Zoho Security & Risk Analysis

wordpress.org/plugins/centous-integration-for-contact-form-7-and-zoho

Integration plugin for Contact Form 7 with Zoho CRM and Zoho Bigin.

0 active installs v1.0 PHP 7.4+ WP 6.7+ Updated Jan 21, 2026
cf7-integrationcontact-form-7crm-integrationzoho-biginzoho-crm
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Centous Integration for Contact Form 7 and Zoho Safe to Use in 2026?

Generally Safe

Score 100/100

Centous Integration for Contact Form 7 and Zoho has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "centous-integration-for-contact-form-7-and-zoho" plugin, in version 1.0, presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and diligently escaping most output. The absence of known CVEs and bundled libraries is also a strength. However, a significant concern arises from the substantial attack surface created by 18 AJAX handlers, all of which lack authentication checks. This makes them prime targets for unauthorized access and potential exploitation. Furthermore, the taint analysis reveals 8 flows with unsanitized paths, identified as high severity. While the specific impact isn't detailed, this suggests a pathway where user-supplied data might not be properly validated or sanitized before being used in a sensitive operation, potentially leading to cross-site scripting (XSS) or other injection vulnerabilities.

While the plugin's history is clean of recorded vulnerabilities, this can be attributed to its early version and potentially limited adoption. The presence of numerous unprotected entry points and high-severity taint flows in this version indicates areas that require immediate attention. The developer has implemented strong practices in SQL and output handling, but the lack of security controls on AJAX handlers and the identified unsanitized paths are critical weaknesses that need to be addressed to improve the plugin's overall security.

Key Concerns

  • AJAX handlers without auth checks
  • High severity taint flows with unsanitized paths
Vulnerabilities
None known

Centous Integration for Contact Form 7 and Zoho Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Centous Integration for Contact Form 7 and Zoho Release Timeline

v1.0Current
Code Analysis
Analyzed Apr 16, 2026

Centous Integration for Contact Form 7 and Zoho Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
56 prepared
Unescaped Output
4
731 escaped
Nonce Checks
21
Capability Checks
23
File Operations
0
External Requests
9
Bundled Libraries
0

SQL Query Safety

100% prepared56 total queries

Output Escaping

99% escaped735 total outputs
Data Flows · Security
8 unsanitized

Data Flow Analysis

18 flows8 with unsanitized paths
handle_ajax (includes/admin/ajax/feeds-save.php:60)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
18 unprotected

Centous Integration for Contact Form 7 and Zoho Attack Surface

Entry Points18
Unprotected18

AJAX Handlers 18

authwp_ajax_cf7zoho_verify_connectionincludes/admin/admin.php:85
authwp_ajax_cf7zoho_disconnectionincludes/admin/admin.php:90
authwp_ajax_cf7zoho_test_connectionincludes/admin/admin.php:95
authwp_ajax_cf7zoho_view_logincludes/admin/admin.php:100
authwp_ajax_cf7zoho_delete_logincludes/admin/admin.php:101
authwp_ajax_cf7zoho_search_logsincludes/admin/admin.php:102
authwp_ajax_cf7zoho_resend_submissionincludes/admin/admin.php:103
authwp_ajax_cf7zoho_bulk_actionincludes/admin/admin.php:104
authwp_ajax_cf7zoho_send_notesincludes/admin/admin.php:109
authwp_ajax_cf7zoho_delete_noteincludes/admin/admin.php:110
authwp_ajax_cf7zoho_filter_feedsincludes/admin/admin.php:116
authwp_ajax_cf7zoho_search_feedsincludes/admin/admin.php:117
authwp_ajax_cf7zoho_delete_feedincludes/admin/admin.php:118
authwp_ajax_cf7zoho_bulk_action_feedincludes/admin/admin.php:119
authwp_ajax_cf7zoho_feed_status_updateincludes/admin/admin.php:120
authwp_ajax_cf7zoho_cf7Fieldsincludes/admin/admin.php:125
authwp_ajax_cf7zoho_save_feedincludes/admin/admin.php:130
authwp_ajax_cf7zoho_get_fieldsincludes/admin/admin.php:131
WordPress Hooks 9
actionadmin_initcentous-integration-for-contact-form-7-and-zoho.php:46
actionadmin_menuincludes/admin/admin.php:68
actionadmin_headincludes/admin/admin.php:69
actionadmin_initincludes/admin/admin.php:132
actionadmin_enqueue_scriptsincludes/core/plugin.php:136
actionadmin_enqueue_scriptsincludes/core/plugin.php:137
actionwp_enqueue_scriptsincludes/core/plugin.php:156
actionwp_enqueue_scriptsincludes/core/plugin.php:157
actionwpcf7_before_send_mailincludes/frontend/forms/cf7/cf7-hooks.php:58
Maintenance & Trust

Centous Integration for Contact Form 7 and Zoho Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 21, 2026
PHP min version7.4
Downloads137

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Centous Integration for Contact Form 7 and Zoho Developer Profile

Centous Solutions

5 plugins · 110 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Centous Integration for Contact Form 7 and Zoho

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/css/admin.css/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/admin.js/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/vendor/select2.min.js/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/feed-edit.js/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/feeds.js/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/logs.js/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/connections.js/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/vendor/codemirror/lib/codemirror.min.js+5 more
Script Paths
/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/admin.js/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/vendor/select2.min.js/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/feed-edit.js/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/feeds.js/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/logs.js/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/connections.js+6 more
Version Parameters
/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/css/admin.css?ver=/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/admin.js?ver=/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/vendor/select2.min.js?ver=/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/feed-edit.js?ver=/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/feeds.js?ver=/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/logs.js?ver=/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/connections.js?ver=/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/vendor/codemirror/lib/codemirror.min.js?ver=/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/vendor/codemirror/addon/edit/matchbrackets.min.js?ver=/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/vendor/codemirror/addon/display/autorefresh.min.js?ver=/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/vendor/codemirror/mode/javascript/javascript.min.js?ver=/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/vendor/codemirror/mode/xml/xml.min.js?ver=/wp-content/plugins/centous-integration-for-contact-form-7-and-zoho/assets/js/vendor/codemirror/mode/htmlmixed/htmlmixed.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
cf7zoho-settings-wrapcf7zoho-sectioncf7zoho-btncf7zoho-btn-primarycf7zoho-btn-defaultcf7zoho-tablecf7zoho-table-headcf7zoho-table-body+16 more
HTML Comments
<!-- BEGIN Plugin --><!-- END Plugin --><!-- IFIS_START --><!-- IFIS_END -->+1 more
Data Attributes
data-cf7zoho-iddata-field-namedata-form-iddata-feed-iddata-module-id
JS Globals
CF7ZOHO_Admincf7zoho_admin_paramscf7zoho_editor_paramscf7zoho_feed_paramscf7zoho_logs_paramscf7zoho_connections_params
REST Endpoints
/wp-json/cf7zoho/v1/settings/wp-json/cf7zoho/v1/feeds/wp-json/cf7zoho/v1/logs
Shortcode Output
<div class="cf7zoho-shortcode-output">
FAQ

Frequently Asked Questions about Centous Integration for Contact Form 7 and Zoho