
Extended CRM for Users Insights Security & Risk Analysis
wordpress.org/plugins/extended-crm-for-users-insightsExtends the CRM functionality of Users Insights - adds new management options to the user groups, user notes and custom user fields features
Is Extended CRM for Users Insights Safe to Use in 2026?
Generally Safe
Score 100/100Extended CRM for Users Insights has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "extended-crm-for-users-insights" v1.2.1 plugin presents a concerning security posture due to significant unprotected entry points. While the static analysis shows no critical or high-severity code signals like dangerous functions, SQL injection risks are high due to 100% of SQL queries not using prepared statements. The plugin also exhibits a low rate of proper output escaping, with only 33% of outputs being safe. The presence of two AJAX handlers without authentication checks is a major concern, creating a broad attack surface that could be exploited by unauthenticated users. The absence of any recorded vulnerabilities in its history might suggest a lack of active targeting or prior patching, but it does not negate the immediate risks identified in the code. Overall, the plugin has a weak security foundation due to unprotected AJAX endpoints and insecure SQL practices, despite a clean vulnerability history.
Key Concerns
- AJAX handlers without authentication checks
- SQL queries without prepared statements
- Low percentage of properly escaped output
Extended CRM for Users Insights Security Vulnerabilities
Extended CRM for Users Insights Code Analysis
SQL Query Safety
Output Escaping
Extended CRM for Users Insights Attack Surface
AJAX Handlers 2
WordPress Hooks 16
Maintenance & Trust
Extended CRM for Users Insights Maintenance & Trust
Maintenance Signals
Community Trust
Extended CRM for Users Insights Alternatives
New User Approve
new-user-approve
WordPress user approval plugin to moderate registrations. Approve or deny real users and prevent fake signups to control who registers on site.
User Access Manager
user-access-manager
With the "User Access Manager"-plugin you can manage the access to your posts, pages and files.
Delete Me
delete-me
Allow users with specific WordPress roles to delete themselves from the Your Profile page or anywhere Shortcodes can be used.
User Import with meta – WP Ultimate CSV Importer Add-on
import-users
Import and export WordPress and WooCommerce users with full user meta, custom fields, billing & shipping details, and membership data.
WP Approve User
wp-approve-user
Adds action links to user table to approve or unapprove user registrations.
Extended CRM for Users Insights Developer Profile
3 plugins · 670 total installs
How We Detect Extended CRM for Users Insights
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/extended-crm-for-users-insights/js/user-list.js/wp-content/plugins/extended-crm-for-users-insights/css/font-awesome.min.css/wp-content/plugins/extended-crm-for-users-insights/css/user-list.css/wp-content/plugins/extended-crm-for-users-insights/js/custom-fields.js/wp-content/plugins/extended-crm-for-users-insights/views/custom-fields/keys-select.htmlextended-crm-for-users-insights/js/user-list.js?ver=extended-crm-for-users-insights/css/font-awesome.min.css?ver=extended-crm-for-users-insights/css/user-list.css?ver=extended-crm-for-users-insights/js/custom-fields.js?ver=HTML / DOM Fingerprints
data-ecui-key-optionswindow.ECUI_VERSION