
DoLeads Integrator Security & Risk Analysis
wordpress.org/plugins/doleads-integratorDoLeads Integrator plugin connects your wordpress website contact form with 'DoLeads' Leads Management System.
Is DoLeads Integrator Safe to Use in 2026?
Generally Safe
Score 85/100DoLeads Integrator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "doleads-integrator" v1.2.2 plugin presents a significant security risk due to its large attack surface of unprotected AJAX handlers. All 12 AJAX entry points lack authentication and authorization checks, meaning any authenticated user could potentially trigger these functions. While the plugin doesn't appear to have a history of publicly disclosed vulnerabilities, this is not a guarantee of current security. The static analysis indicates potential issues with unsanitized paths in taint analysis, specifically two flows identified as high severity. This, coupled with the absence of nonce checks and capability checks on AJAX actions, creates a fertile ground for various attacks, including Cross-Site Request Forgery (CSRF) and potentially more severe vulnerabilities if these unsanitized paths lead to unintended code execution or data leakage. The SQL queries are moderately protected with prepared statements, and output escaping is generally good, but these strengths are overshadowed by the critical lack of input validation and authorization on the AJAX endpoints. The single file operation and external HTTP request also warrant scrutiny in conjunction with the unsanitized paths. Overall, the plugin has several fundamental security weaknesses that require immediate attention.
Key Concerns
- 12 AJAX handlers without auth checks
- 2 Critical severity taint flows (high severity)
- 0 Nonce checks on AJAX
- 0 Capability checks on AJAX
- 3 Flows with unsanitized paths
DoLeads Integrator Security Vulnerabilities
DoLeads Integrator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
DoLeads Integrator Attack Surface
AJAX Handlers 12
WordPress Hooks 6
Maintenance & Trust
DoLeads Integrator Maintenance & Trust
Maintenance Signals
Community Trust
DoLeads Integrator Alternatives
Database Addon for Contact Form 7 – CFDB7
contact-form-cfdb7
Save and manage Contact Form 7 messages. Never lose important data. It is a lightweight contact form 7 database plugin.
ReCaptcha v2 for Contact Form 7
wpcf7-recaptcha
Adds reCaptcha v2 from Contact Form 7 5.0.5 that was dropped on Contact Form 7 5.1
Redirection for Contact Form 7
wpcf7-redirect
Redirect to any page or URL, execute scripts after submission, save data to the database, and unlock additional submission actions for Contact Form 7.
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 – Dynamic Text Extension
contact-form-7-dynamic-text-extension
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
DoLeads Integrator Developer Profile
1 plugin · 2K total installs
How We Detect DoLeads Integrator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/doleads-integrator/includes/js/doleads-integrator-frontend.js/wp-content/plugins/doleads-integrator/includes/css/doleads-integrator-frontend.css/wp-content/plugins/doleads-integrator/includes/js/doleads-integrator-frontend.jsdoleads-integrator/includes/css/doleads-integrator-frontend.css?ver=doleads-integrator/includes/js/doleads-integrator-frontend.js?ver=HTML / DOM Fingerprints
doleads-integrator-input-fielddoleads-integrator-form-wrapperdoleads-integrator-lead-form<!-- Doleads Integrator: Start form capture --><!-- Doleads Integrator: End form capture -->data-doleads-form-iddata-doleads-api-keydoleads_integrator_frontend_params/wp-json/doleads-integrator/v1/capture-lead[doleads_lead_form id=