Connect Contact Form 7 to PipeDrive Security & Risk Analysis

wordpress.org/plugins/connect-cf7-to-pipedrive

Seamlessly integrate Contact Form 7 with PipeDrive to automate your lead management process.

80 active installs v1.0.10 PHP 8.0+ WP 5.3+ Updated May 14, 2025
connectioncontact-form-7crmpipedrive
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Connect Contact Form 7 to PipeDrive Safe to Use in 2026?

Generally Safe

Score 100/100

Connect Contact Form 7 to PipeDrive has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

The plugin "connect-cf7-to-pipedrive" v1.0.10 exhibits a generally strong security posture based on the provided static analysis. There are no identified AJAX handlers or REST API routes without authentication or permission callbacks, and no shortcodes or cron events, resulting in a zero attack surface. The code adheres to good security practices by utilizing prepared statements for all SQL queries and ensuring all output is properly escaped, preventing common injection and cross-site scripting vulnerabilities. The presence of nonce and capability checks further solidifies its defense against unauthorized actions.

However, the taint analysis reveals two flows with unsanitized paths, although they are not classified as critical or high severity. This indicates a potential for issues if these paths are ever exposed to untrusted input or if the severity classification of these flows is inaccurate. The lack of any recorded vulnerabilities in its history is a positive sign, suggesting a history of secure development. The bundling of Guzzle, an external library, warrants a minor check to ensure it is up-to-date, as outdated bundled libraries can introduce vulnerabilities not directly present in the plugin's own code.

In conclusion, the plugin demonstrates good security practices with a minimal attack surface and robust input/output handling. The main area of slight concern lies in the two identified taint flows, which should be investigated further. Its clean vulnerability history is a significant strength. Overall, the plugin appears to be secure, but the identified taint flows represent a minor area for potential improvement and vigilance.

Key Concerns

  • Taint flows with unsanitized paths
  • Bundled library Guzzle
Vulnerabilities
None known

Connect Contact Form 7 to PipeDrive Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Connect Contact Form 7 to PipeDrive Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
47 escaped
Nonce Checks
5
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
1

Bundled Libraries

Guzzle

Output Escaping

100% escaped47 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
getConnectionStatusMessage (src\Admin\Settings.php:67)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Connect Contact Form 7 to PipeDrive Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitconnect-cf7-to-pipedrive.php:76
actionwpcf7_before_send_mailconnect-cf7-to-pipedrive.php:77
actionplugins_loadedconnect-cf7-to-pipedrive.php:88
actionadmin_menusrc\Admin\RegisterMenu.php:28
actionadmin_enqueue_scriptssrc\Admin\ScriptsManager.php:23
Maintenance & Trust

Connect Contact Form 7 to PipeDrive Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 14, 2025
PHP min version8.0
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

Connect Contact Form 7 to PipeDrive Developer Profile

Procoders

7 plugins · 400 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Connect Contact Form 7 to PipeDrive

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/connect-cf7-to-pipedrive/Assets/css/admin.css/wp-content/plugins/connect-cf7-to-pipedrive/Assets/js/admin.js
Version Parameters
connect-cf7-to-pipedrive/Assets/css/admin.css?ver=connect-cf7-to-pipedrive/Assets/js/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
cf7pd_activecf7pd_update_personcf7pd_update_orgcf7pd_fieldscf7pd_access_tokencf7pd_persons+1 more
FAQ

Frequently Asked Questions about Connect Contact Form 7 to PipeDrive