EZFunnels Security & Risk Analysis

wordpress.org/plugins/ezfunnels

Connect your EZFunnels pages to your WordPress blog. Create custom URLs for your pages or set a funnelstep as homepage on your blog.

10 active installs v2.0.0 PHP 5.3+ WP 4.4.8+ Updated Aug 31, 2021
funnelbuilderlanding-pagesoptinpage-buildersales-funnel
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EZFunnels Safe to Use in 2026?

Generally Safe

Score 85/100

EZFunnels has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The ezfunnels v2.0.0 plugin exhibits a concerning security posture primarily due to its large number of unprotected AJAX handlers. While the plugin demonstrates good practices in other areas, such as using prepared statements for all SQL queries and having no recorded vulnerability history, the unprotected AJAX entry points represent a significant attack surface. The absence of proper authentication and authorization checks on these handlers means that any unauthenticated user could potentially trigger them, leading to unintended actions or information disclosure if these handlers perform sensitive operations. The static analysis also indicates that a significant portion of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output without sufficient sanitization. Despite the lack of known vulnerabilities and good SQL practices, the unaddressed AJAX handlers and insufficient output escaping present substantial risks that require immediate attention.

Key Concerns

  • 7 unprotected AJAX handlers
  • 29% properly escaped output
Vulnerabilities
None known

EZFunnels Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

EZFunnels Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
5
2 escaped
Nonce Checks
2
Capability Checks
2
File Operations
4
External Requests
1
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

100% prepared1 total queries

Output Escaping

29% escaped7 total outputs
Attack Surface
7 unprotected

EZFunnels Attack Surface

Entry Points7
Unprotected7

AJAX Handlers 7

authwp_ajax_funnel_popupincludes\controllers\funnels.php:648
authwp_ajax_manage_funnelincludes\controllers\funnels.php:653
authwp_ajax_load_list_funnelsincludes\controllers\funnels.php:658
authwp_ajax_remove_funnelincludes\controllers\funnels.php:659
authwp_ajax_update_step_slugincludes\controllers\funnels.php:661
authwp_ajax_load_previewincludes\controllers\funnels.php:669
authwp_ajax_save_api_keyincludes\controllers\options\manager.php:692
WordPress Hooks 16
actionplugins_loadedezfunnels.php:20
actionplugins_loadedezfunnels.php:102
actionplugins_loadedezfunnels.php:107
actionadmin_enqueue_scriptsincludes\controllers\design.php:219
actionadmin_enqueue_scriptsincludes\controllers\design.php:224
actioninitincludes\controllers\design.php:229
actioninitincludes\controllers\funnels.php:644
actionadmin_initincludes\controllers\funnels.php:646
actiontemplate_redirectincludes\controllers\funnels.php:663
actioninitincludes\controllers\funnels.php:665
actioninitincludes\controllers\funnels.php:667
actionadmin_initincludes\controllers\options\manager.php:680
actionadmin_menuincludes\controllers\options\manager.php:689
actionadmin_initincludes\controllers\options\manager.php:690
filterhttp_request_redirection_countincludes\services\connection.php:495
actionadmin_noticesincludes\services\notice.php:88
Maintenance & Trust

EZFunnels Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.0
Last updatedAug 31, 2021
PHP min version5.3
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

EZFunnels Developer Profile

ezmarketing

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EZFunnels

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ezfunnels/includes/assets/css/backend.css/wp-content/plugins/ezfunnels/includes/assets/css/frontend.css/wp-content/plugins/ezfunnels/includes/assets/js/backend.js/wp-content/plugins/ezfunnels/includes/assets/js/frontend.js
Version Parameters
ezfunnels/includes/assets/css/backend.css?ver=ezfunnels/includes/assets/css/frontend.css?ver=ezfunnels/includes/assets/js/backend.js?ver=ezfunnels/includes/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
ezf-opt-sectionezf-opt-headerezf-opt-controlsezf-opt-contentezf-opt-fieldezf-opt-labelezf-opt-inputezf-opt-description+15 more
Data Attributes
data-ezf-option-typedata-ezf-option-namedata-ezf-opt-id
JS Globals
ezf_options_varsezf_funnels_vars
REST Endpoints
/wp-json/ezfunnels/v1/funnels/wp-json/ezfunnels/v1/funnels/(?P<id>[\d]+)/wp-json/ezfunnels/v1/steps/wp-json/ezfunnels/v1/steps/(?P<id>[\d]+)
FAQ

Frequently Asked Questions about EZFunnels