Flamix: Bitrix24 and Contact Form 7 integrations Security & Risk Analysis

wordpress.org/plugins/flamix-bitrix24-and-contact-forms-7-integrations

Bitrix24 and WordPress Contact Form 7 integration

1K active installs v3.3.0 PHP 7.4+ WP 5.0+ Updated May 12, 2025
b24bitrix24contactformlead
91
A · Safe
CVEs total1
Unpatched0
Last CVEAug 20, 2024
Safety Verdict

Is Flamix: Bitrix24 and Contact Form 7 integrations Safe to Use in 2026?

Generally Safe

Score 91/100

Flamix: Bitrix24 and Contact Form 7 integrations has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Aug 20, 2024Updated 1yr ago
Risk Assessment

The flamix-bitrix24-and-contact-forms-7-integrations plugin v3.3.0 exhibits a mixed security posture. While the static analysis reveals no identified dangerous functions, SQL injection vulnerabilities (as all queries use prepared statements), or taint flows indicating unsanitized user input leading to critical or high severity issues, there are areas of concern. The low percentage of properly escaped output (15%) suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, especially as there are no explicit capability checks or nonce checks on any of the identified entry points. The presence of a single file operation without further context raises a minor flag. The vulnerability history indicates one past CVE classified as 'Exposure of Sensitive Information to an Unauthorized Actor,' which, while currently patched, highlights a historical weakness in data handling. Despite the absence of a large attack surface and critical code signals, the limited output escaping and the past sensitive information exposure vulnerability warrant careful consideration.

Key Concerns

  • Low percentage of properly escaped output
  • Past CVE for sensitive information exposure
  • No explicit capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
1 published

Flamix: Bitrix24 and Contact Form 7 integrations Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-6568medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

Flamix: Bitrix24 and Contact Form 7 integrations <= 3.1.0 - Unauthenticated Full Path Disclosure

Aug 20, 2024 Patched in 3.2.0 (1d)
Version History

Flamix: Bitrix24 and Contact Form 7 integrations Release Timeline

v2.2.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Flamix: Bitrix24 and Contact Form 7 integrations Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

15% escaped13 total outputs
Attack Surface

Flamix: Bitrix24 and Contact Form 7 integrations Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_noticesflamix-bitrix24-and-contact-forms-7-integrations.php:20
actionwpcf7_initflamix-bitrix24-and-contact-forms-7-integrations.php:35
actionwpflamix-bitrix24-and-contact-forms-7-integrations.php:36
actionwpcf7_mail_sentflamix-bitrix24-and-contact-forms-7-integrations.php:37
actionadmin_menuincludes\local\Settings\Menu.php:15
actionadmin_initincludes\local\Settings\Setting.php:23
Maintenance & Trust

Flamix: Bitrix24 and Contact Form 7 integrations Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 12, 2025
PHP min version7.4
Downloads14K

Community Trust

Rating74/100
Number of ratings3
Active installs1K
Developer Profile

Flamix: Bitrix24 and Contact Form 7 integrations Developer Profile

Roman Shkabko

10 plugins · 2K total installs

95
trust score
Avg Security Score
93/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Flamix: Bitrix24 and Contact Form 7 integrations

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flamix-bitrix24-and-contact-forms-7-integrations/assets/css/style.css
Version Parameters
flamix-bitrix24-and-contact-forms-7-integrations/assets/css/style.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Flamix: Bitrix24 and Contact Form 7 integrations