Old Tracking DB for cformsII Security & Risk Analysis

wordpress.org/plugins/cforms2-old-tracking-db

Beginning with version 15 cformsII does not have built-in Tracking Database support anymore. However it allows for arbitrary plugins to process the va …

40 active installs v0.3 PHP + WP 5.2+ Updated Apr 12, 2024
cformscforms2databasedbtracking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Old Tracking DB for cformsII Safe to Use in 2026?

Generally Safe

Score 85/100

Old Tracking DB for cformsII has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The plugin "cforms2-old-tracking-db" v0.3 exhibits a strong security posture based on the provided static analysis. The absence of identified dangerous functions, external HTTP requests, file operations, and the exclusive use of prepared statements for all SQL queries are significant strengths. Furthermore, the analysis indicates that all output is properly escaped, and there are no identified taint flows, suggesting a lack of common vulnerabilities like cross-site scripting (XSS) or SQL injection within the analyzed code paths.

The vulnerability history is equally reassuring, with no known CVEs, critical or high-severity issues, or any recorded vulnerabilities. This suggests a well-maintained and secure codebase over time. However, the complete lack of AJAX handlers, REST API routes, shortcodes, cron events, nonce checks, and capability checks is notable. While this can indicate a very simple plugin with limited functionality, it also means there are no entry points to analyze for security. This can be a double-edged sword; while it reduces the immediate attack surface, it makes it difficult to assess the security of potential future expansions or integrations that might introduce such entry points.

Key Concerns

  • No nonce checks found
  • No capability checks found
  • Zero AJAX handlers and REST API routes
Vulnerabilities
None known

Old Tracking DB for cformsII Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Old Tracking DB for cformsII Release Timeline

v0.3Current
v0.2
v0.1
Code Analysis
Analyzed Apr 16, 2026

Old Tracking DB for cformsII Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
9 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared9 total queries
Attack Surface

Old Tracking DB for cformsII Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actioncforms2_after_processing_actionOldTrackingDB.php:123
actioninitPlugin.php:29
Maintenance & Trust

Old Tracking DB for cformsII Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 12, 2024
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Old Tracking DB for cformsII Developer Profile

bgermann

3 plugins · 4K total installs

71
trust score
Avg Security Score
88/100
Avg Patch Time
2487 days
View full developer profile
Detection Fingerprints

How We Detect Old Tracking DB for cformsII

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
get_cforms_entries
FAQ

Frequently Asked Questions about Old Tracking DB for cformsII