Easily integrate Pipedrive CRM with your WordPress site Security & Risk Analysis

wordpress.org/plugins/contact-manager-for-pipedrive

Contact Manager for Pipedrive lets you automatically create deals in Pipedrive from any WPForms form. Under the form settings, just map form fields t …

40 active installs v1.0 PHP 8.0.10+ WP 5.3+ Updated Feb 15, 2022
crmpipedrivewpforms
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Easily integrate Pipedrive CRM with your WordPress site Safe to Use in 2026?

Generally Safe

Score 85/100

Easily integrate Pipedrive CRM with your WordPress site has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The static analysis of contact-manager-for-pipedrive v1.0 reveals a generally strong security posture at first glance, with no identified dangerous functions, SQL injection vulnerabilities through prepared statements, or file operations. The plugin also avoids making external HTTP requests. However, a significant concern arises from the complete absence of capability checks and nonce checks. This lack of authorization and CSRF protection means that any unauthenticated or authenticated user could potentially trigger actions within the plugin if an entry point were to be discovered or introduced. The output escaping rate of 72% also indicates a moderate risk of cross-site scripting (XSS) vulnerabilities, as a substantial portion of outputs are not being properly sanitized.

The vulnerability history shows no known CVEs, which is a positive indicator of the plugin's past security. However, this absence of historical issues should be viewed in conjunction with the identified code signals. The lack of capability and nonce checks represent fundamental security oversights that could be exploited even without prior documented vulnerabilities. While the plugin demonstrates good practices in areas like SQL query handling, the critical weaknesses in authentication and output sanitization present a tangible risk. A balanced conclusion would be that the plugin has some good internal security practices but suffers from fundamental flaws in user authorization and output sanitization, leaving it vulnerable to exploitation.

Key Concerns

  • No capability checks found
  • No nonce checks found
  • Moderate unescaped output risk
Vulnerabilities
None known

Easily integrate Pipedrive CRM with your WordPress site Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Easily integrate Pipedrive CRM with your WordPress site Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

72% escaped18 total outputs
Attack Surface

Easily integrate Pipedrive CRM with your WordPress site Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_initcontact-manager-for-pipedrive.php:171
actionadmin_menucontact-manager-for-pipedrive.php:172
filterwpforms_builder_settings_sectionsincludes\wpforms\PipedriveWpformsCMFP.php:162
filterwpforms_form_settings_panel_contentincludes\wpforms\PipedriveWpformsCMFP.php:163
actionwpforms_process_completeincludes\wpforms\PipedriveWpformsCMFP.php:164
Maintenance & Trust

Easily integrate Pipedrive CRM with your WordPress site Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 15, 2022
PHP min version8.0.10
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Easily integrate Pipedrive CRM with your WordPress site Developer Profile

zebfross

2 plugins · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Easily integrate Pipedrive CRM with your WordPress site

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/contact-manager-for-pipedrive/css/admin.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Easily integrate Pipedrive CRM with your WordPress site