
Contact Form 7 – SalesKing CRM Addon Security & Risk Analysis
wordpress.org/plugins/contact-form-7-salesking-crm-addonGet your Contact Form 7 data straight into SalesKing CRM.
Is Contact Form 7 – SalesKing CRM Addon Safe to Use in 2026?
Generally Safe
Score 85/100Contact Form 7 – SalesKing CRM Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "contact-form-7-salesking-crm-addon" v1.1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and properly escaping a high percentage of its outputs. The absence of file operations and external HTTP requests, along with no known vulnerabilities in its history, are also strong indicators of careful development. However, significant concerns arise from its attack surface analysis. The presence of one unprotected AJAX handler is a critical weakness, as it represents a direct entry point for potential malicious activity without any authentication or authorization checks. This lack of protection on an AJAX endpoint could be exploited to trigger unintended actions or expose sensitive information.
While the taint analysis did not reveal critical or high-severity issues, the presence of two flows with unsanitized paths warrants attention. Coupled with the single unprotected AJAX handler, this suggests that even though direct critical vulnerabilities aren't immediately apparent from the static analysis, the pathway to exploitation exists. The plugin's vulnerability history being completely clean is a good sign, but it does not negate the risks presented by the current code's weaknesses, particularly the unprotected AJAX endpoint. Overall, the plugin has some strengths in its coding practices, but the unprotected AJAX handler significantly elevates its risk profile.
Key Concerns
- Unprotected AJAX handler
- Flows with unsanitized paths (2)
- No nonce checks
- No capability checks
Contact Form 7 – SalesKing CRM Addon Security Vulnerabilities
Contact Form 7 – SalesKing CRM Addon Code Analysis
Output Escaping
Data Flow Analysis
Contact Form 7 – SalesKing CRM Addon Attack Surface
AJAX Handlers 1
WordPress Hooks 8
Maintenance & Trust
Contact Form 7 – SalesKing CRM Addon Maintenance & Trust
Maintenance Signals
Community Trust
Contact Form 7 – SalesKing CRM Addon Alternatives
Juridic-OS Connector
juridic-os-connector
El plugin oficial de Juridic-OS para integración de formularios de contacto con sistemas de gestión legal.
MangoFp
mangofp
Manage Contact Form 7 messages directly in WordPress like leads in the CRM system.
WorkZen Connector
workzen-connector
Connect your WordPress forms to WorkZen CRM and never miss a lead again.
AFI – The Easiest Integration Plugin
advanced-form-integration
Connect any WordPress form or event to 200+ apps — no code. Send leads, orders, and signups to your CRM, email, or sheets in minutes.
Lenix Leads Collector
lenix-elementor-leads-addon
Leads Collector, Collects forms entries from Elementor,Cf7,WPForms and more with export to CSV.
Contact Form 7 – SalesKing CRM Addon Developer Profile
1 plugin · 10 total installs
How We Detect Contact Form 7 – SalesKing CRM Addon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/contact-form-7-salesking-crm-addon/assets/js/admin.jscontact-form-7-salesking-crm-addon/assets/js/admin.js?ver=HTML / DOM Fingerprints
wpcf7-sk-activename="wpcf7-sk[active]"id="wpcf7-sk-active"name="wpcf7-sk[email]"id="wpcf7-sk-email"name="wpcf7-sk[last_name]"id="wpcf7-sk-last_name"+8 moreWPCF7_SK_VERSION/wp-json/wpcf7-sk/v1/test