
CXTailor Funnels Security & Risk Analysis
wordpress.org/plugins/cxtailor-funnelsEdit customer journeys, video funnels and CX Tailor experiences directly from WordPress without switching between platforms.
Is CXTailor Funnels Safe to Use in 2026?
Generally Safe
Score 100/100CXTailor Funnels has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cxtailor-funnels" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. It demonstrates good practices by ensuring all SQL queries utilize prepared statements and all output is properly escaped, eliminating common web vulnerabilities like SQL injection and cross-site scripting (XSS) through these avenues. Furthermore, the absence of dangerous functions, file operations, and bundled libraries reduces the potential for complex code-level exploits.
However, there are a few areas that warrant attention. The presence of two REST API routes without explicit permission callbacks, while not immediately exploitable without further context, represents an potential area for unauthorized access if not properly secured by WordPress's default capabilities or custom checks within the plugin's logic. The plugin also makes two external HTTP requests, which, if not carefully managed, could be a vector for server-side request forgery (SSRF) or data exfiltration if the target URLs are untrusted or compromised. The lack of nonce checks on AJAX handlers, although there are none in this version, is a significant security gap that would be concerning if AJAX functionality were introduced in future versions without proper implementation.
The plugin's vulnerability history is remarkably clean, with no recorded CVEs. This indicates a potential for well-written code or a lack of extensive security auditing. Coupled with the clean taint analysis results, this suggests the current version is likely safe from known complex vulnerabilities. However, the absence of vulnerabilities does not guarantee future safety, and the identified potential weaknesses in the REST API and external requests should be addressed proactively. Overall, the plugin has a good foundation, but minor improvements in authentication for API routes and careful management of external requests would further bolster its security.
Key Concerns
- REST API routes without permission callbacks
- External HTTP requests
CXTailor Funnels Security Vulnerabilities
CXTailor Funnels Code Analysis
Output Escaping
CXTailor Funnels Attack Surface
REST API Routes 2
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
CXTailor Funnels Maintenance & Trust
Maintenance Signals
Community Trust
CXTailor Funnels Alternatives
CartFlows – Funnel Builder & Checkout Plugin for WooCommerce
cartflows
1 WordPress funnel builder & WooCommerce checkout plugin. Boost AOV with one-click upsells, order bumps & high-converting checkout pages.
FunnelKit – Funnel Builder for WooCommerce Checkout
funnel-builder
Create high-converting WooCommerce checkout pages, WooCommerce thank you pages & sales funnels with the highest-rated WordPress funnel builder.
Woopra Analytics Plugin
woopra
Track who is on your website, what pages they're browsing, actions they're taking, articles they're reading and more.
Order Bump for WooCommerce
molongui-bump-offer
Boost sales by promoting products as upsells before payment. Customers can accept the deal from the Checkout page with just one click
Fast ClickFunnels
fast-clickfunnels
Connect your ClickFunnels account to your FastMember WordPress site. Use the ClickFunnels webhook to automatically add users to FastMember products.
CXTailor Funnels Developer Profile
1 plugin · 0 total installs
How We Detect CXTailor Funnels
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cxtailor-funnels/assets/block.js/wp-content/plugins/cxtailor-funnels/assets/block.csshttps://admin.cxtailor.com/cxtailorfunnel.jscxtailor-funnels/assets/block.js?ver=cxtailor-funnels/assets/block.css?ver=HTML / DOM Fingerprints
cxtf-editor-placeholdercxtailor-embed-wrappercxtailor-embedcxtailor-funneldata-funnel-idCXTfGlobals/wp-json/cxtailor/v1/login/wp-json/cxtailor/v1/funnels<div class="cxtf-editor-placeholder"><strong>CX Tailor Funnel</strong><br/><div class="cxtailor-embed-wrapper"<div class="cxtailor-embed"