
CrankWheel Instant Demos Security & Risk Analysis
wordpress.org/plugins/crankwheelPlug and play lead capture form. Fully configurable. Find an agent to call the prospect right away, or have them schedule a meeting, or tell them &quo …
Is CrankWheel Instant Demos Safe to Use in 2026?
Generally Safe
Score 85/100CrankWheel Instant Demos has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Crankwheel plugin v1.0.2 exhibits a generally positive security posture, with a notable absence of known vulnerabilities and a commitment to secure coding practices such as using prepared statements for all SQL queries. The static analysis indicates a low number of entry points and no critical or high-severity taint flows, which are strong indicators of a well-developed and secure plugin. Furthermore, the plugin does not bundle external libraries, reducing the risk of introducing vulnerabilities from outdated dependencies.
However, there are areas for improvement. The plugin has one unprotected REST API route, which represents a significant attack surface that is not properly secured. While the overall number of entry points is low, the lack of a permission callback on this single REST API route could allow unauthorized access to its functionality. Additionally, while only 64% of outputs are properly escaped, this is a moderate concern, as unescaped output can lead to cross-site scripting (XSS) vulnerabilities, especially if user-controlled data is involved. The presence of two nonce checks is positive, but the absence of capability checks on any of the AJAX handlers is a missed opportunity to further strengthen security, particularly if these handlers perform sensitive actions.
In conclusion, Crankwheel v1.0.2 is a relatively secure plugin, primarily due to its clean vulnerability history and good SQL handling. The main weaknesses lie in the unprotected REST API endpoint and the moderate rate of output escaping. Addressing these specific points would significantly enhance the plugin's security.
Key Concerns
- Unprotected REST API route
- Moderate output escaping percentage
- No capability checks on AJAX handlers
CrankWheel Instant Demos Security Vulnerabilities
CrankWheel Instant Demos Release Timeline
CrankWheel Instant Demos Code Analysis
Output Escaping
Data Flow Analysis
CrankWheel Instant Demos Attack Surface
AJAX Handlers 4
REST API Routes 1
WordPress Hooks 7
Maintenance & Trust
CrankWheel Instant Demos Maintenance & Trust
Maintenance Signals
Community Trust
CrankWheel Instant Demos Alternatives
BrainCert Virtual Classroom
html5-virtual-classroom
Transform the way you educate with BrainCert's Virtual Classroom API. Immerse your users in a world of interactive, dynamic, and effective online …
2ConnectMe – Video Chat, Screen Share & Stripe Payments
business-chat-room-2connectme
The complete customer interaction center plugin. Offer video/voice chat, see & share screens, remote control and Stripe payment. Free Plan available.
Engage for WooCommerce
engage-by-zubi
Engage is a Growth Platform for E-commerce. Using Engage, an e-commerce store get all the tools required to drastically enhance the results of everyth …
Flowbox
flowbox
Flowbox helps brands leverage and distribute social content throughout the buyer journey to increase engagement, social proof and sales.
Video Call Button by Gruveo
gruveo-call-button
Let your website visitors call you with voice and video using the Gruveo button. No account or installs are needed for callers!
CrankWheel Instant Demos Developer Profile
1 plugin · 10 total installs
How We Detect CrankWheel Instant Demos
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/crankwheel/includes/assets/scripts/admin.js/wp-content/plugins/crankwheel/includes/assets/styles/admin.css/wp-content/plugins/crankwheel/includes/assets/scripts/admin.jscrankwheel/style.css?ver=crankwheel/script.js?ver=HTML / DOM Fingerprints
cw/wp-json/crankwheel/v1/api