Clio Grow Form Security & Risk Analysis

wordpress.org/plugins/clio-grow-form

The Clio Grow Wordpress plugin enables law firms who use Clio Grow to automatically capture leads from their website or blog into the Clio Grow CRM.

1K active installs v1.0.4 PHP + WP 4.0+ Updated Nov 17, 2025
clioclio-growcontact-formlaw-firmlawyer
98
A · Safe
CVEs total3
Unpatched0
Last CVEOct 15, 2024
Download
Safety Verdict

Is Clio Grow Form Safe to Use in 2026?

Generally Safe

Score 98/100

Clio Grow Form has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Oct 15, 2024Updated 4mo ago
Risk Assessment

The clio-grow-form plugin v1.0.4 exhibits a generally good static security posture with no identified critical or high severity taint flows and all SQL queries utilizing prepared statements. The plugin also demonstrates good output escaping practices, with all 107 outputs properly escaped. The presence of 3 known medium severity vulnerabilities, specifically Cross-site Scripting (XSS), in its history is a significant concern, even though none are currently unpatched in this version. The last reported vulnerability was quite recent, suggesting ongoing security issues. While the code analysis shows a small attack surface and good use of nonces, the historical pattern of XSS vulnerabilities, coupled with the lack of capability checks on any entry points, warrants caution. A key weakness is the absence of capability checks on any entry points, meaning that potentially sensitive actions could be triggered by users without the necessary permissions. This, combined with the historical XSS issues, means that while the immediate code analysis is promising, the plugin's past indicates a propensity for certain types of vulnerabilities.

Key Concerns

  • Multiple medium XSS vulnerabilities historically
  • No capability checks on entry points
  • Recent vulnerability reported (2024-10-15)
Vulnerabilities
3

Clio Grow Form Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
2 CVEs in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2024-49276medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Clio Grow <= 1.0.2 - Reflected Cross-Site Scripting

Oct 15, 2024 Patched in 1.0.3 (10d)
CVE-2024-8802medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Clio Grow <= 1.0.2 - Reflected Cross-Site Scripting

Oct 3, 2024 Patched in 1.0.3 (21d)
CVE-2023-22683medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Clio Grow <= 1.0.0 - Authenticated (Admin+) Stored Cross Site Scripting

Feb 20, 2023 Patched in 1.0.1 (337d)
Code Analysis
Analyzed Mar 16, 2026

Clio Grow Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
107 escaped
Nonce Checks
5
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped107 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
settings_page (includes\class-grow-form-settings.php:524)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Clio Grow Form Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[grow-contact-form] includes\class-grow-form.php:100
WordPress Hooks 9
actioninitincludes\class-grow-form-settings.php:45
actionadmin_initincludes\class-grow-form-settings.php:48
actionadmin_menuincludes\class-grow-form-settings.php:51
actionwp_enqueue_scriptsincludes\class-grow-form.php:103
actionwp_enqueue_scriptsincludes\class-grow-form.php:104
actionplugins_loadedincludes\class-grow-form.php:105
actionadmin_enqueue_scriptsincludes\class-grow-form.php:108
actionadmin_enqueue_scriptsincludes\class-grow-form.php:109
actioninitincludes\class-grow-form.php:118
Maintenance & Trust

Clio Grow Form Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 17, 2025
PHP min version
Downloads13K

Community Trust

Rating46/100
Number of ratings3
Active installs1K
Developer Profile

Clio Grow Form Developer Profile

cliogrow

1 plugin · 1K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
123 days
View full developer profile
Detection Fingerprints

How We Detect Clio Grow Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clio-grow-form/assets/css/admin.css/wp-content/plugins/clio-grow-form/assets/css/form.css/wp-content/plugins/clio-grow-form/assets/js/admin.js/wp-content/plugins/clio-grow-form/assets/js/form.js/wp-content/plugins/clio-grow-form/assets/js/settings.js
Script Paths
/wp-content/plugins/clio-grow-form/assets/js/admin.js/wp-content/plugins/clio-grow-form/assets/js/form.js/wp-content/plugins/clio-grow-form/assets/js/settings.js
Version Parameters
/wp-content/plugins/clio-grow-form/assets/css/admin.css?ver=/wp-content/plugins/clio-grow-form/assets/css/form.css?ver=/wp-content/plugins/clio-grow-form/assets/js/admin.js?ver=/wp-content/plugins/clio-grow-form/assets/js/form.js?ver=/wp-content/plugins/clio-grow-form/assets/js/settings.js?ver=

HTML / DOM Fingerprints

CSS Classes
clio-grow-form-wrapclio-grow-form-container
HTML Comments
<!-- Clio Grow Form Settings --><!-- End Clio Grow Form Settings --><!-- Clio Grow Form --><!-- End Clio Grow Form -->
Data Attributes
data-clio-grow-form-id
JS Globals
grow_form_params
Shortcode Output
[grow_form]
FAQ

Frequently Asked Questions about Clio Grow Form