
Collect Lead Form Security & Risk Analysis
wordpress.org/plugins/collect-lead-formCollect Lead Form is a lightweight WordPress plugin to capture leads or use as an Ajax-powered contact form.
Is Collect Lead Form Safe to Use in 2026?
Generally Safe
Score 100/100Collect Lead Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "collect-lead-form" plugin v1.0.3 exhibits a generally good security posture with several positive indicators. The absence of known vulnerabilities and CVEs, coupled with the fact that all SQL queries utilize prepared statements and a high percentage of outputs are properly escaped, suggests a developer who is mindful of common security pitfalls. The presence of nonces and capability checks further reinforces this notion, indicating an effort to protect against common WordPress attack vectors.
However, a significant concern arises from the static analysis, specifically the REST API. There is one REST API route that lacks permission callbacks. This represents a direct entry point into the plugin's functionality that is not properly secured, meaning any unauthenticated user could potentially interact with this endpoint. While the total attack surface is low, this single unprotected entry point warrants attention.
Given the clean vulnerability history and the use of secure coding practices in other areas, the overall risk is currently assessed as moderate. The plugin's strengths lie in its clean history and the secure handling of database interactions and output. The primary weakness is the unauthenticated REST API endpoint, which, if exploited, could lead to unintended plugin behavior or data exposure. Addressing this single unprotected entry point would significantly bolster the plugin's security.
Key Concerns
- REST API route without permission callback
Collect Lead Form Security Vulnerabilities
Collect Lead Form Code Analysis
SQL Query Safety
Output Escaping
Collect Lead Form Attack Surface
REST API Routes 1
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
Collect Lead Form Maintenance & Trust
Maintenance Signals
Community Trust
Collect Lead Form Alternatives
Lead Generation Form
lead-generation-form
Create lead forms with drag-and-drop builder, capture leads, and export data easily.
Saksh Callback Request Form
saksh-callback-request-form
Inspired by zerodha, Kotek Mahidra bank, JIO fibre lead generation form I setup this form it first ask users email ID and mobile number and then send …
Simple Lead Generator
simple-lead-generator
🔥 Easily Generate Leads with an AJAX-Based Form 🔥
Ninja Forms – The Contact Form Builder That Grows With You
ninja-forms
The 100% beginner friendly WordPress form builder. Drag & drop form fields to build beautiful, professional contact forms in minutes.
Contact Form & SMTP Plugin for WordPress by PirateForms
pirate-forms
A simple and effective WordPress contact form & SMTP plugin. Compatible with best themes out there, is both a secure and responsive contact form p …
Collect Lead Form Developer Profile
4 plugins · 0 total installs
How We Detect Collect Lead Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/collect-lead-form/assets/css/app.css/wp-content/plugins/collect-lead-form/assets/js/clcf-main.js/wp-content/plugins/collect-lead-form/assets/css/carbon-fields-theme.css/wp-content/plugins/collect-lead-form/assets/js/clcf-main.jscollect-lead-form/assets/css/app.css?ver=collect-lead-form/assets/js/clcf-main.js?ver=collect-lead-form/assets/css/carbon-fields-theme.css?ver=HTML / DOM Fingerprints
clcf-form-wrap<!--[if gte mso 9]><!--<![endif]-->data-bs-toggledata-bs-targetclcf_rest_url/wp-json/clcf/v1/collect-lead-form[collect-lead-form]