
Devs CRM – Manage tasks, attendance and teams all together Security & Risk Analysis
wordpress.org/plugins/devs-crmDevCRM simplifies project management and member attendance and tasks tracking for your teams.
Is Devs CRM – Manage tasks, attendance and teams all together Safe to Use in 2026?
Use With Caution
Score 56/100Devs CRM – Manage tasks, attendance and teams all together has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The "devs-crm" plugin v1.1.9 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to secure coding practices regarding SQL queries, utilizing prepared statements exclusively, and ensuring all output is properly escaped. The presence of numerous nonce and capability checks also indicates an awareness of WordPress security best practices.
However, significant concerns arise from the attack surface analysis. The plugin exposes 54 REST API routes, with a notable 2 routes lacking permission callbacks. This creates a direct entry point for unauthenticated users to interact with potentially sensitive functionality. The taint analysis, while reporting zero flows, may not be comprehensive if not all entry points were thoroughly analyzed for potential taint. The plugin's vulnerability history is particularly concerning, with 2 currently unpatched medium severity CVEs, both attributed to missing authorization. This pattern suggests a recurring weakness in how the plugin handles user permissions, which is a critical aspect of web application security.
In conclusion, while the plugin has strengths in its handling of database queries and output, the identified unpatched vulnerabilities and the presence of unprotected REST API endpoints represent significant security risks. The recurring theme of missing authorization in past vulnerabilities demands immediate attention. The plugin requires urgent remediation of its unpatched CVEs and a thorough review of its REST API endpoints to ensure proper authorization checks are in place.
Key Concerns
- 2 REST API routes without permission callbacks
- 2 currently unpatched medium severity CVEs
Devs CRM – Manage tasks, attendance and teams all together Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Devs CRM – Manage tasks, attendance and teams all together <= 1.1.8 - Unauthenticated Information Expsoure
Devs CRM – Manage tasks, attendance and teams all together <= 1.1.8 - Missing Authorization to Unauthenticated Lead Tag Update
Devs CRM – Manage tasks, attendance and teams all together Release Timeline
Devs CRM – Manage tasks, attendance and teams all together Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Devs CRM – Manage tasks, attendance and teams all together Attack Surface
REST API Routes 54
Shortcodes 2
WordPress Hooks 17
Scheduled Events 2
Maintenance & Trust
Devs CRM – Manage tasks, attendance and teams all together Maintenance & Trust
Maintenance Signals
Community Trust
Devs CRM – Manage tasks, attendance and teams all together Alternatives
Flamingo
flamingo
A trustworthy message storage plugin for Contact Form 7.
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
FluentCRM – Email Newsletter, Automation, Email Marketing, Email Campaigns, Optins, Leads, and CRM Solution
fluent-crm
The easiest and fastest Email Marketing, Newsletter, Marketing Automation Plugin & CRM Solution for WordPress
LeadConnector
leadconnector
LeadConnector: It helps you to add the LeadConnector chat widget and the LeadConnector funnel pages to your WordPress website.
Jetpack CRM – Clients, Leads, Invoices, Billing, Email Marketing, & Automation
zero-bs-crm
The CRM for small businesses. Manage leads, invoicing, billing, email marketing, clients, contacts, quotes, automation. Works with WooCommerce too.
Devs CRM – Manage tasks, attendance and teams all together Developer Profile
3 plugins · 100 total installs
How We Detect Devs CRM – Manage tasks, attendance and teams all together
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/devs-crm/build/frontend.js/wp-content/plugins/devs-crm/build/index.css/wp-content/plugins/devs-crm/build/admin.jswp-content/plugins/devs-crm/build/frontend.jswp-content/plugins/devs-crm/build/index.csswp-content/plugins/devs-crm/build/admin.jsdevs-crm/build/frontend.js?ver=devs-crm/build/index.css?ver=devs-crm/build/admin.js?ver=HTML / DOM Fingerprints
devscrm-wrapperdevs_crm_accountdevs_crm_admindcrm_shortcode_containerdcrm_lead_form_containerappLocalizer.apiUrlappLocalizer.nonceappLocalizer.pluginUrl/wp-json/devs-crm/v1/add-attendance<div class="devscrm-wrapper"><div id="dcrm_shortcode_container"></div></div><div class="devscrm-wrapper"><div id="dcrm_lead_form_container"></div></div>