CRMZT Connector for Zoho by TechArk Security & Risk Analysis

wordpress.org/plugins/crmzt-integration-with-zoho-for-gravity-forms

Integrate Gravity Forms with Zoho CRM to automatically send form submissions as Leads, Contacts, or entries in custom modules.

0 active installs v1.3.2 PHP 7.2+ WP 5.0+ Updated Jan 30, 2026
contact-formgravity-formslead-capturezohozoho-crm
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CRMZT Connector for Zoho by TechArk Safe to Use in 2026?

Generally Safe

Score 100/100

CRMZT Connector for Zoho by TechArk has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "crmzt-integration-with-zoho-for-gravity-forms" plugin v1.3.2 presents a mixed security posture. While it exhibits good practices in terms of output escaping and SQL query preparedness, significant concerns arise from its attack surface. All 12 identified AJAX handlers lack authentication checks, creating a substantial risk of unauthorized actions being performed if these handlers are accessible to unauthenticated users. The presence of the "unserialize" function, while not currently exploited in taint analysis, is a known risk vector that should be handled with extreme caution, especially when dealing with user-supplied input.

The vulnerability history is currently clean, with no recorded CVEs. This is a positive indicator and suggests the plugin has been relatively secure in the past. However, the lack of historical vulnerabilities does not negate the risks identified in the static analysis. The plugin demonstrates strengths in areas like output escaping, with 91% of outputs properly escaped, and 77% of SQL queries utilizing prepared statements. These are good security practices.

In conclusion, while the plugin has a clean vulnerability history and good practices in output handling and SQL, the unprotected AJAX endpoints and the use of "unserialize" represent significant potential weaknesses. The high number of unprotected entry points is the most immediate and pressing concern, warranting careful review and implementation of appropriate access controls. The use of "unserialize" should be re-evaluated or secured with robust validation if it handles any external data.

Key Concerns

  • 12 unprotected AJAX handlers
  • Use of unserialize function
Vulnerabilities
None known

CRMZT Connector for Zoho by TechArk Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

CRMZT Connector for Zoho by TechArk Code Analysis

Dangerous Functions
2
Raw SQL Queries
3
10 prepared
Unescaped Output
8
84 escaped
Nonce Checks
7
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
1

Dangerous Functions Found

unserialize$leadData = unserialize($item['leaddata']);admin\class-crmzt-zoho-integration-admin.php:1189
unserialize$responseData = unserialize($item['respsonedata']);admin\class-crmzt-zoho-integration-admin.php:1196

Bundled Libraries

Select2

SQL Query Safety

77% prepared13 total queries

Output Escaping

91% escaped92 total outputs
Data Flows
All sanitized

Data Flow Analysis

8 flows
CRMZT_genartRefreshToken (admin\class-crmzt-zoho-integration-admin.php:314)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
12 unprotected

CRMZT Connector for Zoho by TechArk Attack Surface

Entry Points12
Unprotected12

AJAX Handlers 12

noprivwp_ajax_CRMZT_genartRefreshTokenincludes\class-crmzt-zoho-integration.php:161
authwp_ajax_CRMZT_genartRefreshTokenincludes\class-crmzt-zoho-integration.php:162
noprivwp_ajax_CRMZT_storemaxminddataincludes\class-crmzt-zoho-integration.php:164
authwp_ajax_CRMZT_storemaxminddataincludes\class-crmzt-zoho-integration.php:165
noprivwp_ajax_CRMZT_resetRefreshTokenincludes\class-crmzt-zoho-integration.php:167
authwp_ajax_CRMZT_resetRefreshTokenincludes\class-crmzt-zoho-integration.php:168
noprivwp_ajax_CRMZT_leadmoduleincludes\class-crmzt-zoho-integration.php:170
authwp_ajax_CRMZT_leadmoduleincludes\class-crmzt-zoho-integration.php:171
noprivwp_ajax_CRMZT_mappingSaveincludes\class-crmzt-zoho-integration.php:173
authwp_ajax_CRMZT_mappingSaveincludes\class-crmzt-zoho-integration.php:174
noprivwp_ajax_CRMZT_mappingDeleteincludes\class-crmzt-zoho-integration.php:176
authwp_ajax_CRMZT_mappingDeleteincludes\class-crmzt-zoho-integration.php:177
WordPress Hooks 11
actionadmin_enqueue_scriptsincludes\class-crmzt-zoho-integration.php:157
actionadmin_enqueue_scriptsincludes\class-crmzt-zoho-integration.php:158
actionadmin_menuincludes\class-crmzt-zoho-integration.php:159
actiongform_after_submissionincludes\class-crmzt-zoho-integration.php:179
actiongform_custom_merge_tagsincludes\class-crmzt-zoho-integration.php:180
actiongform_field_value_visitor_fromincludes\class-crmzt-zoho-integration.php:182
actionadmin_post_nopriv_download_lead_jsonincludes\class-crmzt-zoho-integration.php:184
actionadmin_post_download_lead_jsonincludes\class-crmzt-zoho-integration.php:185
actionadmin_noticesincludes\class-crmzt-zoho-integration.php:187
actionwp_enqueue_scriptsincludes\class-crmzt-zoho-integration.php:201
actionwp_enqueue_scriptsincludes\class-crmzt-zoho-integration.php:202
Maintenance & Trust

CRMZT Connector for Zoho by TechArk Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 30, 2026
PHP min version7.2
Downloads713

Community Trust

Rating100/100
Number of ratings4
Active installs0
Developer Profile

CRMZT Connector for Zoho by TechArk Developer Profile

TechArk Solutions

4 plugins · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CRMZT Connector for Zoho by TechArk

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/crmzt-integration-with-zoho-for-gravity-forms/admin/css/crmzt-zoho-integration-admin.css/wp-content/plugins/crmzt-integration-with-zoho-for-gravity-forms/admin/css/font-awesome.min.css/wp-content/plugins/crmzt-integration-with-zoho-for-gravity-forms/admin/css/select2.min.css/wp-content/plugins/crmzt-integration-with-zoho-for-gravity-forms/admin/css/sweet-alert.css/wp-content/plugins/crmzt-integration-with-zoho-for-gravity-forms/admin/js/crmzt-zoho-integration-admin.js
Script Paths
/wp-content/plugins/crmzt-integration-with-zoho-for-gravity-forms/admin/js/crmzt-zoho-integration-admin.js
Version Parameters
/wp-content/plugins/crmzt-integration-with-zoho-for-gravity-forms/admin/css/crmzt-zoho-integration-admin.css?ver=/wp-content/plugins/crmzt-integration-with-zoho-for-gravity-forms/admin/css/font-awesome.min.css?ver=/wp-content/plugins/crmzt-integration-with-zoho-for-gravity-forms/admin/css/select2.min.css?ver=/wp-content/plugins/crmzt-integration-with-zoho-for-gravity-forms/admin/css/sweet-alert.css?ver=/wp-content/plugins/crmzt-integration-with-zoho-for-gravity-forms/admin/js/crmzt-zoho-integration-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
crmzt-zoho-integration-admin-css
JS Globals
CRMZT_Zoho_Integration_Admin
FAQ

Frequently Asked Questions about CRMZT Connector for Zoho by TechArk