
WP Gravity Forms Zoho CRM and Bigin Security & Risk Analysis
wordpress.org/plugins/gf-zohoGravity Forms Zoho CRM Add-On Sends Gravity Forms entries to Zoho CRM and Bigin.
Is WP Gravity Forms Zoho CRM and Bigin Safe to Use in 2026?
Generally Safe
Score 95/100WP Gravity Forms Zoho CRM and Bigin has a strong security track record. Known vulnerabilities have been patched promptly.
The gf-zoho plugin v1.3.0 presents a mixed security posture. While it demonstrates a decent effort in implementing security measures, such as a substantial number of nonce and capability checks, and a majority of SQL queries utilizing prepared statements, significant concerns remain. The presence of a single unprotected AJAX handler is a critical entry point that could be exploited if not properly secured. Furthermore, the taint analysis revealing a flow with an unsanitized path and a high severity indicates a potential vulnerability that could lead to serious security breaches. The plugin's vulnerability history, including past issues like Open Redirect, Deserialization, and XSS, coupled with a high-severity past vulnerability, suggests a recurring pattern of weaknesses that require diligent attention. While the current version has no unpatched CVEs, the historical context coupled with the current code analysis findings suggests a need for ongoing vigilance and robust security practices.
Key Concerns
- Unprotected AJAX handler
- Taint flow with unsanitized path (High severity)
- Dangerous function: unserialize
- Past high severity vulnerability
- Bundled library (Select2)
WP Gravity Forms Zoho CRM and Bigin Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
WP Gravity Forms Zoho CRM and Bigin <= 1.2.8 - Open Redirect
Gravity Forms Zoho CRM and Bigin <= 1.2.9 - Unauthenticated PHP Object Injection
CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting
WP Gravity Forms Zoho CRM and Bigin Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Gravity Forms Zoho CRM and Bigin Attack Surface
AJAX Handlers 1
WordPress Hooks 36
Maintenance & Trust
WP Gravity Forms Zoho CRM and Bigin Maintenance & Trust
Maintenance Signals
Community Trust
WP Gravity Forms Zoho CRM and Bigin Alternatives
Zoho SalesIQ – Live chat, chatbots, and visitor tracking
zoho-salesiq
Identify, engage and convert website visitors with live chat and visitor analytics.
AFI – The Easiest Integration Plugin
advanced-form-integration
Connect any WordPress form or event to 200+ apps — no code. Send leads, orders, and signups to your CRM, email, or sheets in minutes.
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin
cf7-zoho
Send Contact Form 7, WPforms, Elementor, Formidable, Ninja Forms and many other contact form submissions to zoho CRM and Bigin.
Zoho CRM Lead Magnet
zoho-crm-forms
Websites are one of the most important sources of leads for your business.
Integration for WooCommerce and Zoho CRM, Books, Invoice, Inventory, Bigin
woo-zoho
WooCommerce Zoho Connector allows you to quickly integrate WooCommerce Orders with Zoho CRM, Books, Inventory and Invoice.
WP Gravity Forms Zoho CRM and Bigin Developer Profile
32 plugins · 105K total installs
How We Detect WP Gravity Forms Zoho CRM and Bigin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-zoho/admin/js/crm-function.js/wp-content/plugins/gf-zoho/admin/css/admin-style.css/wp-content/plugins/gf-zoho/admin/js/notice.js/wp-content/plugins/gf-zoho/includes/js/gf-zoho-feeds.js/wp-content/plugins/gf-zoho/admin/js/gf-zoho-add-on.js/wp-content/plugins/gf-zoho/assets/css/vxg-style.css/wp-content/plugins/gf-zoho/assets/js/vxg-script.jsgf-zoho/admin/js/crm-function.js?ver=gf-zoho/admin/css/admin-style.css?ver=gf-zoho/admin/js/notice.js?ver=gf-zoho/includes/js/gf-zoho-feeds.js?ver=gf-zoho/admin/js/gf-zoho-add-on.js?ver=gf-zoho/assets/css/vxg-style.css?ver=gf-zoho/assets/js/vxg-script.js?ver=HTML / DOM Fingerprints
vx_noticegf-zoho-feed-settingsgf-zoho-add-on-page<!-- START: GF Zoho PRO Plugin API --><!-- END: GF Zoho PRO Plugin API --><!-- START: GF Zoho PRO Plugin Add-Ons --><!-- END: GF Zoho PRO Plugin Add-Ons -->+2 moredata-id="gravity"data-id="zoho-feed"window.vx_zoho_feeds_objwindow.gf_zoho_script_params{zoholink_{zohoid_