
EZFunnels Security & Risk Analysis
wordpress.org/plugins/ezfunnelsConnect your EZFunnels pages to your WordPress blog. Create custom URLs for your pages or set a funnelstep as homepage on your blog.
Is EZFunnels Safe to Use in 2026?
Generally Safe
Score 85/100EZFunnels has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ezfunnels v2.0.0 plugin exhibits a concerning security posture primarily due to its large number of unprotected AJAX handlers. While the plugin demonstrates good practices in other areas, such as using prepared statements for all SQL queries and having no recorded vulnerability history, the unprotected AJAX entry points represent a significant attack surface. The absence of proper authentication and authorization checks on these handlers means that any unauthenticated user could potentially trigger them, leading to unintended actions or information disclosure if these handlers perform sensitive operations. The static analysis also indicates that a significant portion of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output without sufficient sanitization. Despite the lack of known vulnerabilities and good SQL practices, the unaddressed AJAX handlers and insufficient output escaping present substantial risks that require immediate attention.
Key Concerns
- 7 unprotected AJAX handlers
- 29% properly escaped output
EZFunnels Security Vulnerabilities
EZFunnels Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
EZFunnels Attack Surface
AJAX Handlers 7
WordPress Hooks 16
Maintenance & Trust
EZFunnels Maintenance & Trust
Maintenance Signals
Community Trust
EZFunnels Alternatives
ONTRApages
ontrapages
ONTRApages for WordPress allows Ontraport Premium users to connect to their accounts and easily publish their landing pages on their own WordPress sit …
Templates For PluginOps Landing Page Builder
post-list-wp
Templates for Landing Page Builder By PluginOps.
EngageBay Landing Pages – Responsive landing pages for lead generation and conversions
engagebay-landing-page-builder
The simplest way to create beautiful, responsive and high converting landing pages in minutes without writing any code. Improve conversion rates, run …
SEO Landing Page Generator
seo-landing-page-generator
Generate landing pages in bulk based on location with randomized content. Update thousands of landing pages in seconds.
WP Funnel Manager
wp-funnel-manager
Organises content into multi-step funnels.
EZFunnels Developer Profile
2 plugins · 20 total installs
How We Detect EZFunnels
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ezfunnels/includes/assets/css/backend.css/wp-content/plugins/ezfunnels/includes/assets/css/frontend.css/wp-content/plugins/ezfunnels/includes/assets/js/backend.js/wp-content/plugins/ezfunnels/includes/assets/js/frontend.jsezfunnels/includes/assets/css/backend.css?ver=ezfunnels/includes/assets/css/frontend.css?ver=ezfunnels/includes/assets/js/backend.js?ver=ezfunnels/includes/assets/js/frontend.js?ver=HTML / DOM Fingerprints
ezf-opt-sectionezf-opt-headerezf-opt-controlsezf-opt-contentezf-opt-fieldezf-opt-labelezf-opt-inputezf-opt-description+15 moredata-ezf-option-typedata-ezf-option-namedata-ezf-opt-idezf_options_varsezf_funnels_vars/wp-json/ezfunnels/v1/funnels/wp-json/ezfunnels/v1/funnels/(?P<id>[\d]+)/wp-json/ezfunnels/v1/steps/wp-json/ezfunnels/v1/steps/(?P<id>[\d]+)