Flooows Elementor PRO Lead DB Security & Risk Analysis

wordpress.org/plugins/flooows-form-leads-store

Elementor PRO doesn't store your form submissions? Let's do it with Flooows Elementor PRO Lead DB. Store, view and export your form submissi …

10 active installs v1.2.1 PHP 5.5+ WP 4.5+ Updated May 25, 2020
elementor-pro-contact-formelementor-pro-extensionelementor-pro-formelementor-pro-leadselementor-pro-leads-store
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Flooows Elementor PRO Lead DB Safe to Use in 2026?

Generally Safe

Score 85/100

Flooows Elementor PRO Lead DB has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "flooows-form-leads-store" v1.2.1 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any known vulnerabilities in its history is a significant positive indicator. The code demonstrates good practices by exclusively using prepared statements for its single SQL query and performing capability checks. However, there are a couple of areas for improvement and potential concern.

The static analysis reveals that while the overall attack surface is zero, there is one instance of an unsanitized path identified in the taint analysis. This suggests a potential, albeit likely low-severity, risk if user input were to be channeled through this path without proper sanitization. Furthermore, the fact that 22% of output is not properly escaped, while not necessarily critical on its own, introduces a potential for Cross-Site Scripting (XSS) vulnerabilities if the unescaped outputs handle user-controlled data.

In conclusion, the plugin is currently in a relatively secure state, especially given its clean vulnerability history and good SQL handling. The primary concerns are the single unsanitized path and the percentage of unescaped output, which, while not flagged as critical, represent areas where a vulnerability could be introduced. Addressing these points would further solidify the plugin's security.

Key Concerns

  • Flows with unsanitized paths found
  • Output escaping not fully implemented
Vulnerabilities
None known

Flooows Elementor PRO Lead DB Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Flooows Elementor PRO Lead DB Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Flooows Elementor PRO Lead DB Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
5
18 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

78% escaped23 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
ffls_export_admin (flooows_form_leads_store_for_elementor_pro.php:19)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Flooows Elementor PRO Lead DB Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuflooows_form_leads_store_for_elementor_pro.php:14
actionplugins_loadedflooows_form_leads_store_for_elementor_pro.php:15
actionadmin_action_ffls_exportflooows_form_leads_store_for_elementor_pro.php:16
actionadmin_enqueue_scriptsflooows_form_leads_store_for_elementor_pro.php:103
actionadmin_enqueue_scriptsflooows_form_leads_store_for_elementor_pro.php:104
actionelementor_pro/forms/new_recordflooows_form_leads_store_for_elementor_pro.php:105
Maintenance & Trust

Flooows Elementor PRO Lead DB Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedMay 25, 2020
PHP min version5.5
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Flooows Elementor PRO Lead DB Developer Profile

fuertedev01

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Flooows Elementor PRO Lead DB

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/flooows-form-leads-store/assets/css/ffls.css
Script Paths
/wp-content/plugins/flooows-form-leads-store/assets/js/ffls-script.js
Version Parameters
flooows-form-leads-store/assets/css/ffls.css?ver=flooows-form-leads-store/assets/js/ffls-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
ffls-heading-inline
Data Attributes
onclick="showLeads(
FAQ

Frequently Asked Questions about Flooows Elementor PRO Lead DB