
FuseDesk Security & Risk Analysis
wordpress.org/plugins/fusedeskIntegrate with FuseDesk so your CRM contacts, members, and visitors can open support cases in your FuseDesk app or start a Live Chat from your website
Is FuseDesk Safe to Use in 2026?
Mostly Safe
Score 74/100FuseDesk is generally safe to use. 3 past CVEs were resolved.
The Fusedesk plugin version 6.8.1 exhibits a concerning security posture due to a significant number of unprotected entry points and a history of multiple medium-severity vulnerabilities, including Cross-Site Scripting. While the plugin demonstrates good practices in SQL query handling and output escaping, the presence of 8 unprotected AJAX handlers presents a substantial attack surface. This lack of authentication on these handlers means that any unauthenticated user could potentially trigger plugin functionality, leading to unexpected behavior or exploitation if further vulnerabilities exist.
Taint analysis indicates no critical or high-severity unsanitized flows, which is a positive sign. However, the fact that all 5 analyzed flows involved unsanitized paths, even if they didn't reach a critical severity, warrants caution. The plugin's history of 3 medium CVEs, all related to Cross-Site Scripting, is a significant red flag. While there is currently one unpatched vulnerability, the recurring nature of XSS issues suggests a persistent weakness in how user-supplied data is handled before being displayed.
In conclusion, Fusedesk v6.8.1 has notable strengths in its SQL and output escaping practices. However, these are overshadowed by the high number of unprotected AJAX endpoints and a history of XSS vulnerabilities. The potential for abuse of the open attack surface, combined with past XSS issues, indicates a moderate to high risk for users of this version.
Key Concerns
- Multiple unprotected AJAX handlers
- Unpatched CVEs
- Medium severity CVEs historically
- All taint flows had unsanitized paths
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
FuseDesk Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
FuseDesk <= 6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'emailtext' Shortcode Attribute
FuseDesk <= 6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via successredirect Parameter
FuseDesk <= 6.6.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
FuseDesk Release Timeline
FuseDesk Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
FuseDesk Attack Surface
AJAX Handlers 8
Shortcodes 3
WordPress Hooks 11
Maintenance & Trust
FuseDesk Maintenance & Trust
Maintenance Signals
Community Trust
FuseDesk Alternatives
Keap Official Opt-in Forms
infusionsoft-official-opt-in-forms
Build your email subscriber list from visitors to your WordPress website with Keap's Official Opt-in Forms plugin.
Integration for Keap/infusionsoft and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms
cf7-infusionsoft
Send Contact Form 7, WPForms, Elementor, Ninja Forms, Contact Form Entries Plugin and many other contact form submissions to infusionsoft/Keap.
WP Gravity Forms Keap/Infusionsoft
gf-infusionsoft
Gravity Forms Keap/infusionsoft Add-on sends Gravity Forms entries to infusionsoft/Keap CRM.
Gravity Forms Keap Feed
systasis-gf-infusionsoft-feed
Sync form submissions between Gravity Forms and Keap. This version won't work after 31-Dec-2026. See https://systasis.co/category/gfif for more.
SegMetrics Marketing Analytics
segmetrics
Connect your SegMetrics account to get unparalleled insights into your visitor journey.
FuseDesk Developer Profile
5 plugins · 8K total installs
How We Detect FuseDesk
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fusedesk/fusedesk.css/wp-content/plugins/fusedesk/fusedesk.js/wp-content/plugins/fusedesk/fusedesk-blocks/fusedesk-blocks.js/wp-content/plugins/fusedesk/fusedesk.js/wp-content/plugins/fusedesk/fusedesk-blocks/fusedesk-blocks.jsfusedesk/fusedesk.css?ver=fusedesk/fusedesk.js?ver=fusedesk-blocks/fusedesk-blocks.js?ver=HTML / DOM Fingerprints
fusedesk-live-chatFuseDesk (WordPress Plugin)Copyright (C) 2013-2026 Asandia, Corp.These API endpoints let admins request our cached data via the WordPress API. We can even optionallyforce a data refresh. Simply call:+5 moredata-fusedesk-appnamedata-fusedesk-apikeydata-fusedesk-defaultrepdata-fusedesk-defaultdepartmentdata-fusedesk-plannamedata-fusedesk-footerlink+3 morefusedesk_params/wp-json/fusedesk/v1/settings/wp-json/fusedesk/v1/partners[fusedesk_newcase][fusedesk_mycases][fusedesk_teamcases]