
Funnel Security & Risk Analysis
wordpress.org/plugins/funnelStreamline Your Marketing: Effortlessly Navigate User Conversion Paths
Is Funnel Safe to Use in 2026?
Generally Safe
Score 92/100Funnel has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "funnel" plugin v1.4.2 exhibits a generally strong security posture based on the static analysis. The complete absence of identified vulnerabilities in its history, coupled with a lack of critical or high-severity taint flows, is highly encouraging. The plugin also demonstrates good practices such as 100% usage of prepared statements for SQL queries and the presence of nonce and capability checks, albeit limited in number.
However, a significant concern arises from the output escaping analysis. With 53 total outputs and only 53% properly escaped, there's a substantial portion of output that remains vulnerable to cross-site scripting (XSS) attacks. This indicates a potential weakness where user-supplied data, if not carefully handled before being displayed, could be injected with malicious scripts. While the attack surface is currently zero, this relies on the assumption that the provided analysis fully captured all potential entry points. The limited number of checks (nonce and capability) also suggests that a more comprehensive approach to securing these limited entry points would be beneficial.
In conclusion, while the "funnel" plugin has an excellent track record and avoids common pitfalls like raw SQL or exploitable taint flows, the significant amount of improperly escaped output presents a tangible risk of XSS vulnerabilities. The strengths lie in its clean vulnerability history and secure data handling for database operations. The primary weakness is the insufficient output escaping, which needs immediate attention to mitigate potential XSS risks.
Key Concerns
- Insufficient output escaping (47% unsanitized)
Funnel Security Vulnerabilities
Funnel Code Analysis
Output Escaping
Data Flow Analysis
Funnel Attack Surface
WordPress Hooks 23
Maintenance & Trust
Funnel Maintenance & Trust
Maintenance Signals
Community Trust
Funnel Alternatives
Constant Contact Forms
constant-contact-forms
The official Constant Contact plugin adds a contact form to your WordPress site to quickly capture information from visitors.
Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation
sumome
Sumo is trusted by over 600,000 businesses — small and large — in growing their email lists, customer base, and revenue online.
Leadster
leadster-marketing-conversacional
Leadster Marketing Conversacional: O Futuro da Geração de Leads
Hotjar for WordPress
sws-hotjar
The Hotjar for WordPress plugin adds the tracking code provided by hotjar to your site.
Quiz Leads
quizleads
Motive This plugin is used to generate leads by taking user through very easy questions.
Funnel Developer Profile
5 plugins · 100 total installs
How We Detect Funnel
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/funnel/css/funnel-style.cssHTML / DOM Fingerprints
nav-tabnav-tab-activedescriptionbuttonbutton-primarybutton-largename="funnel_settings"value="funnel_settings"name="funnel_pages_enabled"value="1"name="funnel_emails_subject"name="funnel_emails_body"+5 more