Flamix: Bitrix24 and Divi Contact Form integration Security & Risk Analysis

wordpress.org/plugins/flamix-bitrix24-and-divi-contact-form-integration

Bitrix24 and WordPress Divi Contact Form integration

10 active installs v1.2.0 PHP 7.4+ WP 5.0+ Updated May 12, 2025
b24bitrix24crmintegrationlead
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Flamix: Bitrix24 and Divi Contact Form integration Safe to Use in 2026?

Generally Safe

Score 92/100

Flamix: Bitrix24 and Divi Contact Form integration has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'flamix-bitrix24-and-divi-contact-form-integration' plugin v1.2.0 appears to have a strong security posture in several key areas. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the complete avoidance of dangerous functions and raw SQL queries, with all SQL operations utilizing prepared statements, is a significant strength. The lack of file operations and external HTTP requests also reduces potential vulnerabilities.

However, there are concerning indicators within the static analysis. The very low percentage of properly escaped output (15%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. With 13 outputs analyzed and only a small fraction properly escaped, user-supplied data or data displayed by the plugin is likely to be rendered without adequate sanitization, making it susceptible to injection attacks. The absence of nonce checks and capability checks, especially given the limited attack surface, means that any potential, albeit currently undiscovered, entry points could be exploited without proper authorization or integrity verification.

The vulnerability history being completely clear of any known CVEs is a positive sign, indicating that the plugin has not had publicly disclosed vulnerabilities. This, combined with the absence of critical taint flows, might suggest a relatively safe plugin. However, the low output escaping rate is a significant red flag that the vulnerability history might not be capturing due to a lack of discovery rather than inherent security. In conclusion, while the plugin demonstrates good practices in its architecture and SQL handling, the poor output escaping practices present a critical and actionable security concern.

Key Concerns

  • Low output escaping rate
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Flamix: Bitrix24 and Divi Contact Form integration Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Flamix: Bitrix24 and Divi Contact Form integration Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Flamix: Bitrix24 and Divi Contact Form integration Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

15% escaped13 total outputs
Attack Surface

Flamix: Bitrix24 and Divi Contact Form integration Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionadmin_noticesflamix-bitrix24-and-divi-contact-form-integration.php:19
actionwpflamix-bitrix24-and-divi-contact-form-integration.php:33
actionet_pb_contact_form_submitflamix-bitrix24-and-divi-contact-form-integration.php:34
actionadmin_menuincludes\local\Settings\Menu.php:15
actionadmin_initincludes\local\Settings\Setting.php:23
Maintenance & Trust

Flamix: Bitrix24 and Divi Contact Form integration Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 12, 2025
PHP min version7.4
Downloads836

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Flamix: Bitrix24 and Divi Contact Form integration Developer Profile

Roman Shkabko

10 plugins · 2K total installs

95
trust score
Avg Security Score
93/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Flamix: Bitrix24 and Divi Contact Form integration

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flamix-bitrix24-and-divi-contact-form-integration/assets/css/style.css/wp-content/plugins/flamix-bitrix24-and-divi-contact-form-integration/assets/js/scripts.js
Script Paths
/wp-content/plugins/flamix-bitrix24-and-divi-contact-form-integration/assets/js/scripts.js
Version Parameters
flamix-bitrix24-and-divi-contact-form-integration/assets/css/style.css?ver=flamix-bitrix24-and-divi-contact-form-integration/assets/js/scripts.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Flamix: Bitrix24 and Divi Contact Form integration