Forms Shortcode for BeaconCRM (community) Security & Risk Analysis

wordpress.org/plugins/forms-shortcode-for-beaconcrm

Easily embed BeaconCRM forms into WordPress using a simple shortcode.

0 active installs v1.0.0 PHP + WP 5.0+ Updated Unknown
beaconcrmcrmembedformsshortcode
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Forms Shortcode for BeaconCRM (community) Safe to Use in 2026?

Generally Safe

Score 100/100

Forms Shortcode for BeaconCRM (community) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "forms-shortcode-for-beaconcrm" v1.0.0 exhibits a strong initial security posture based on the provided static analysis. The absence of dangerous functions, use of prepared statements for all SQL queries, proper output escaping, and lack of file operations or external HTTP requests are all positive indicators. Crucially, there are no identified taint flows with unsanitized paths, suggesting that the plugin is not immediately vulnerable to common injection attacks. The attack surface is minimal, with only one shortcode and no unprotected entry points, which further contributes to its apparent security. The plugin's vulnerability history is also clean, with no recorded CVEs, indicating a lack of previously discovered flaws.

However, a significant concern arises from the complete absence of nonce checks and capability checks. While the static analysis did not identify any direct vulnerabilities stemming from this, it represents a significant potential weakness. This means that any authenticated user, regardless of their role or privileges, could potentially trigger the shortcode's functionality, which could be exploited if the shortcode's internal logic were to contain a vulnerability that could be triggered by a lower-privileged user. This lack of granular authorization is a notable gap in its security implementation. The plugin's strengths lie in its clean code regarding data handling and query execution, but the absence of security controls for its single entry point is a critical oversight that could lead to future issues if not addressed.

Key Concerns

  • Missing nonce checks for shortcode
  • Missing capability checks for shortcode
Vulnerabilities
None known

Forms Shortcode for BeaconCRM (community) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Forms Shortcode for BeaconCRM (community) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Forms Shortcode for BeaconCRM (community) Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[beaconcrm_form] forms-shortcode-for-beaconcrm.php:40
WordPress Hooks 2
actioninitforms-shortcode-for-beaconcrm.php:20
actionwp_enqueue_scriptsforms-shortcode-for-beaconcrm.php:21
Maintenance & Trust

Forms Shortcode for BeaconCRM (community) Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version
Downloads262

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Forms Shortcode for BeaconCRM (community) Developer Profile

cygnetuk

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Forms Shortcode for BeaconCRM (community)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/forms-shortcode-for-beaconcrm/beaconcrm.min.js
Script Paths
https://static.beaconproducts.co.uk/js-sdk/production/beaconcrm.min.js
Version Parameters
forms-shortcode-for-beaconcrm/beaconcrm.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
beacon-form
HTML Comments
<!-- BeaconCRM Form ID not provided -->
Data Attributes
data-accountdata-form
Shortcode Output
<div class="beacon-form" data-account="" data-form="
FAQ

Frequently Asked Questions about Forms Shortcode for BeaconCRM (community)