Custom WP Zapier Security & Risk Analysis

wordpress.org/plugins/custom-wp-zapier

Custom WP Zapier is one stop solution for integrating apis to WP.

100 active installs v1.3.7 PHP 7.2+ WP 5.8+ Updated Oct 14, 2022
api-integrationcustom-zapiercutom-wp-zappierwebhookszappier-integration
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Custom WP Zapier Safe to Use in 2026?

Generally Safe

Score 85/100

Custom WP Zapier has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The custom-wp-zapier plugin v1.3.7 exhibits a strong security posture based on the provided static analysis. The absence of identified dangerous functions, a high percentage of SQL queries utilizing prepared statements, and the complete sanitization of output escaping are commendable practices. Furthermore, the plugin demonstrates careful implementation by including a nonce check and a capability check, along with zero identified external HTTP requests or bundled libraries. The vulnerability history is also clear, with no recorded CVEs, suggesting a lack of previously exploited weaknesses.

However, a notable area for potential improvement lies in the plugin's attack surface. While the current analysis shows zero entry points, this is often a transient state. If any functionality is added in the future without proper authentication or permission checks, it could introduce significant risks. The single file operation is also something to monitor, as mishandling file access can lead to various security issues.

In conclusion, the plugin appears robust and well-secured at this version, demonstrating good development hygiene. The lack of historical vulnerabilities further strengthens this assessment. The primary concern, if any, would be the potential for future additions to the attack surface to be implemented insecurely, although no such issues are currently detected. The absence of taint analysis results is also noteworthy; while it might indicate no flows were found, it's also possible that the analysis tool had limitations or specific configurations were not met.

Vulnerabilities
None known

Custom WP Zapier Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Custom WP Zapier Release Timeline

v1.3.7Current
v1.3.6
v1.3.5
v1.3.4
v1.3.3
v1.3.2
v1.3.1
v1.3.0
Code Analysis
Analyzed Mar 16, 2026

Custom WP Zapier Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
38 prepared
Unescaped Output
0
14 escaped
Nonce Checks
1
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

97% prepared39 total queries

Output Escaping

100% escaped14 total outputs
Attack Surface

Custom WP Zapier Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionrest_api_initcustom-wp-zapier-rest-settings.php:33
actionadmin_menucustom-wp-zapier-settings.php:31
actionadmin_enqueue_scriptscustom-wp-zapier-settings.php:32
actionpre_user_querycustom-wp-zapier-user-activity.php:40
actionadmin_noticesentry.php:40
actionadmin_noticesentry.php:45
Maintenance & Trust

Custom WP Zapier Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedOct 14, 2022
PHP min version7.2
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Custom WP Zapier Developer Profile

sahibzkhan

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom WP Zapier

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-wp-zapier/custom-wp-zapier-admin.css/wp-content/plugins/custom-wp-zapier/custom-wp-zapier-admin.js
Script Paths
/wp-content/plugins/custom-wp-zapier/custom-wp-zapier-admin.js
Version Parameters
custom-wp-zapier/custom-wp-zapier-admin.css?ver=custom-wp-zapier/custom-wp-zapier-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-custom-zapier-settings-wrapzapier-thinkingloader-textloaderwp-custom-zapier-field-mappings-form
Data Attributes
data-option_name="CUSTOM_WP_ZAPIER_SETTINGS"
JS Globals
CUSTOM_WP_ZAPIER_PLUGIN_VERSIONCUSTOM_WP_ZAPIER_PLUGIN_NAMECUSTOM_WP_ZAPIER_PLUGIN_DIRCUSTOM_WP_ZAPIER_SETTINGS_GROUPCUSTOM_WP_ZAPIER_SETTINGS_MAIN_PAGE
REST Endpoints
/wp-json/custom-wp-zapier/v1/sf-post-hook
Shortcode Output
<div class="wrap wp-custom-zapier-settings-wrap col-md-12"><div class="zapier-thinking"><span class="loader-text">Please Wait...</span><span class="loader"></span>
FAQ

Frequently Asked Questions about Custom WP Zapier