Cubo CRM Security & Risk Analysis

wordpress.org/plugins/cubo-crm

Seamlessly integrate Contact Form 7 with Cubo CRM to manage deals and automate workflows directly from your WordPress site.

0 active installs v1.3.2 PHP 7.2+ WP 5.0+ Updated Jun 2, 2025
apiautomationcontact-form-7crmintegration
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Cubo CRM Safe to Use in 2026?

Generally Safe

Score 92/100

Cubo CRM has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The Cubo CRM plugin, version 1.3.2, presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all its SQL queries, which significantly mitigates SQL injection risks. The absence of critical or high-severity taint flows and dangerous functions further suggests a degree of code quality. However, the plugin has a notable attack surface with 6 total entry points, of which 3 are AJAX handlers that lack authentication checks. This is a significant concern, as it opens potential avenues for unauthorized actions if these handlers can be triggered externally. The relatively low percentage of properly escaped output (69%) also indicates a moderate risk of cross-site scripting (XSS) vulnerabilities.

Key Concerns

  • AJAX handlers without authentication checks
  • Moderate output escaping coverage
Vulnerabilities
None known

Cubo CRM Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Cubo CRM Release Timeline

v1.0.0
Code Analysis
Analyzed Apr 6, 2026

Cubo CRM Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
14 prepared
Unescaped Output
92
207 escaped
Nonce Checks
7
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared14 total queries

Output Escaping

69% escaped299 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
cubo_crm_render_smtp_page (includes/smtp.php:50)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Cubo CRM Attack Surface

Entry Points6
Unprotected3

AJAX Handlers 5

authwp_ajax_cubo_crm_processcubo-crm.php:65
noprivwp_ajax_cubo_crm_processcubo-crm.php:66
authwp_ajax_cubo_crm_resend_failedcubo-crm.php:67
authwp_ajax_cubo_crm_resend_failedincludes/admin/failed.php:130
authwp_ajax_cubo_crm_remove_failedincludes/admin/failed.php:131

Shortcodes 1

[cubo_crm_hidden] cubo-crm.php:70
WordPress Hooks 17
actionwp_enqueue_scriptscubo-crm.php:47
actionwpcf7_before_send_mailcubo-crm.php:68
filterwpcf7_form_hidden_fieldscubo-crm.php:69
actionadmin_enqueue_scriptsincludes/admin/failed.php:148
actionadmin_enqueue_scriptsincludes/admin/forms.php:244
actionadmin_menuincludes/admin/menu.php:6
actionadmin_initincludes/admin/settings.php:6
actionadmin_initincludes/admin/settings.php:41
actionadmin_enqueue_scriptsincludes/admin/settings.php:178
actionadmin_initincludes/database.php:55
filterwpcf7_form_hidden_fieldsincludes/forms.php:29
actionwp_footerincludes/processing.php:63
filterwpcf7_feedback_responseincludes/processing.php:74
actionwp_footerincludes/processing.php:129
filterwpcf7_feedback_responseincludes/processing.php:140
actionwpcf7_before_send_mailincludes/processing.php:179
actionphpmailer_initincludes/smtp.php:9
Maintenance & Trust

Cubo CRM Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.6
Last updatedJun 2, 2025
PHP min version7.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Cubo CRM Developer Profile

Cubo Suite

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Cubo CRM

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cubo-crm/assets/js/cubo-crm.js
Script Paths
/wp-content/plugins/cubo-crm/assets/js/cubo-crm.js
Version Parameters
cubo-crm/assets/js/cubo-crm.js?ver=

HTML / DOM Fingerprints

CSS Classes
resend-singleremove-singleresend-selectedremove-selected
HTML Comments
<!-- Tabela personalizada justifica uso direto -->
Data Attributes
data-id
JS Globals
cuboCrm
REST Endpoints
/wp-ajax.php
FAQ

Frequently Asked Questions about Cubo CRM