
id:CRM Contacts & Companies Security & Risk Analysis
wordpress.org/plugins/idcrm-contacts-companiesThis is first free module from id:CRM to organize contacts and companies.
Is id:CRM Contacts & Companies Safe to Use in 2026?
Generally Safe
Score 100/100id:CRM Contacts & Companies has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'idcrm-contacts-companies' plugin v3.1.3 exhibits a generally good security posture based on the provided static analysis. The absence of any known CVEs and a clean vulnerability history are positive indicators. The plugin demonstrates strong adherence to secure coding practices, with a high percentage of SQL queries using prepared statements and a good proportion of outputs being properly escaped. Nonce and capability checks are present, suggesting an effort to protect against common WordPress vulnerabilities. However, the presence of 20 instances of the `unserialize` function is a significant concern. While no specific taint flows were flagged as critical or high severity, `unserialize` is inherently risky as it can lead to remote code execution if used with untrusted input. Furthermore, the plugin performs external HTTP requests, which could be a vector for supply chain attacks or data exfiltration if not handled carefully. The absence of any reported vulnerabilities might also be due to limited security auditing or a lack of public disclosure rather than a guarantee of perfect security. Overall, while the plugin has strengths in its implementation of common security checks, the heavy reliance on `unserialize` presents a notable risk that warrants further investigation and potential remediation.
Key Concerns
- Dangerous function 'unserialize' used extensively
- External HTTP requests performed
id:CRM Contacts & Companies Security Vulnerabilities
id:CRM Contacts & Companies Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
id:CRM Contacts & Companies Attack Surface
WordPress Hooks 110
Maintenance & Trust
id:CRM Contacts & Companies Maintenance & Trust
Maintenance Signals
Community Trust
id:CRM Contacts & Companies Alternatives
CRM Salesforce LearnDash Integration
crm-salesforce-learndash-integration
New yet simple salesforce experience
WP Gravity Forms Salesforce
gf-salesforce-crmperks
Gravity Forms Salesforce Add-on sends Gravity forms entries to salesforce CRM.
Object Sync for Salesforce
object-sync-for-salesforce
Object Sync for Salesforce maps and syncs data between Salesforce objects and WordPress objects.
Object Data Sync for Salesforce Integration with WP, Woo, Gravity, WPForms, Ninja, CF7 & more
object-data-sync-for-salesforce
Automate data sync with our Salesforce Integration plugin. Supports integrations with WooCommerce, Gravity, Ninja, CF7, WPForms, Event Calendar & more
Surbma | SalesAutopilot Shortcode
surbma-salesautopilot-shortcode
A simple shortcode to include SalesAutopilot forms into WordPress.
id:CRM Contacts & Companies Developer Profile
1 plugin · 0 total installs
How We Detect id:CRM Contacts & Companies
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/idcrm-contacts-companies/admin/css/admin-user.css/wp-content/plugins/idcrm-contacts-companies/assets/css/quill.snow.css/wp-content/plugins/idcrm-contacts-companies/assets/libs/bootstrap-material-datetimepicker/css/bootstrap-material-datetimepicker.css/wp-content/plugins/idcrm-contacts-companies/admin/js/admin-user.js/wp-content/plugins/idcrm-contacts-companies/admin/js/admin-user-manage.js/wp-content/plugins/idcrm-contacts-companies/assets/libs/moment/moment.js/wp-content/plugins/idcrm-contacts-companies/assets/libs/moment/locale//wp-content/plugins/idcrm-contacts-companies/assets/js/quill.js+1 more/wp-content/plugins/idcrm-contacts-companies/admin/js/admin-user.js/wp-content/plugins/idcrm-contacts-companies/admin/js/admin-user-manage.js/wp-content/plugins/idcrm-contacts-companies/assets/libs/moment/moment.js/wp-content/plugins/idcrm-contacts-companies/assets/libs/moment/locale//wp-content/plugins/idcrm-contacts-companies/assets/js/quill.js/wp-content/plugins/idcrm-contacts-companies/assets/libs/bootstrap-material-datetimepicker/js/bootstrap-material-date/wp-content/plugins/idcrm-contacts-companies/admin/css/admin-user.css?ver=/wp-content/plugins/idcrm-contacts-companies/assets/css/quill.snow.css?ver=/wp-content/plugins/idcrm-contacts-companies/assets/libs/bootstrap-material-datetimepicker/css/bootstrap-material-datetimepicker.css?ver=/wp-content/plugins/idcrm-contacts-companies/admin/js/admin-user.js?ver=/wp-content/plugins/idcrm-contacts-companies/admin/js/admin-user-manage.js?ver=/wp-content/plugins/idcrm-contacts-companies/assets/libs/moment/moment.js?ver=/wp-content/plugins/idcrm-contacts-companies/assets/libs/moment/locale//wp-content/plugins/idcrm-contacts-companies/assets/js/quill.js?ver=/wp-content/plugins/idcrm-contacts-companies/assets/libs/bootstrap-material-datetimepicker/js/bootstrap-material-date?ver=HTML / DOM Fingerprints
idcrm-admin-settingsdata-nonce="idcrm-admin-settings"idcrm_settingsidcrm_admin_data