Forms Shortcode for BeaconCRM (community) Security & Risk Analysis
wordpress.org/plugins/forms-shortcode-for-beaconcrmEasily embed BeaconCRM forms into WordPress using a simple shortcode.
Is Forms Shortcode for BeaconCRM (community) Safe to Use in 2026?
Generally Safe
Score 100/100Forms Shortcode for BeaconCRM (community) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "forms-shortcode-for-beaconcrm" v1.0.0 exhibits a strong initial security posture based on the provided static analysis. The absence of dangerous functions, use of prepared statements for all SQL queries, proper output escaping, and lack of file operations or external HTTP requests are all positive indicators. Crucially, there are no identified taint flows with unsanitized paths, suggesting that the plugin is not immediately vulnerable to common injection attacks. The attack surface is minimal, with only one shortcode and no unprotected entry points, which further contributes to its apparent security. The plugin's vulnerability history is also clean, with no recorded CVEs, indicating a lack of previously discovered flaws.
However, a significant concern arises from the complete absence of nonce checks and capability checks. While the static analysis did not identify any direct vulnerabilities stemming from this, it represents a significant potential weakness. This means that any authenticated user, regardless of their role or privileges, could potentially trigger the shortcode's functionality, which could be exploited if the shortcode's internal logic were to contain a vulnerability that could be triggered by a lower-privileged user. This lack of granular authorization is a notable gap in its security implementation. The plugin's strengths lie in its clean code regarding data handling and query execution, but the absence of security controls for its single entry point is a critical oversight that could lead to future issues if not addressed.
Key Concerns
- Missing nonce checks for shortcode
- Missing capability checks for shortcode
Forms Shortcode for BeaconCRM (community) Security Vulnerabilities
Forms Shortcode for BeaconCRM (community) Code Analysis
Output Escaping
Forms Shortcode for BeaconCRM (community) Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Forms Shortcode for BeaconCRM (community) Maintenance & Trust
Maintenance Signals
Community Trust
Forms Shortcode for BeaconCRM (community) Alternatives
HubSpot All-In-One Marketing – Forms, Popups, Live Chat
leadin
The CRM, Sales, and Marketing WordPress plugin to grow your business better. Capture and engage web visitors with free live chat, forms, CRM, email ma …
Advanced iFrame
advanced-iframe
Include content the way YOU like in an iframe that can hide and modify elements, does auto-height, forward parameters and does many, many more...
Insert Pages
insert-pages
Insert Pages lets you embed any WordPress content (e.g., pages, posts, custom post types) into other WordPress content using the Shortcode API.
BSK PDF Manager
bsk-pdf-manager
Manage your PDFs / documents by category, can be display in list, columns and dropdown. Easy to embed a PDF contnet into post / page.
Spreaker Shortcode
spreaker-shortcode
A simple and easy way to embed Spreaker player into your WordPress blog.
Forms Shortcode for BeaconCRM (community) Developer Profile
1 plugin · 0 total installs
How We Detect Forms Shortcode for BeaconCRM (community)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/forms-shortcode-for-beaconcrm/beaconcrm.min.jshttps://static.beaconproducts.co.uk/js-sdk/production/beaconcrm.min.jsforms-shortcode-for-beaconcrm/beaconcrm.min.js?ver=HTML / DOM Fingerprints
beacon-form<!-- BeaconCRM Form ID not provided -->data-accountdata-form<div class="beacon-form" data-account="" data-form="