Visitor Analytics and Lead Generation Plugin by Inbound Rocket Security & Risk Analysis

wordpress.org/plugins/inbound-rocket

The easiest way to double your leads. Inbound Rocket is an easy-to-use marketing automation and lead tracking plugin for WordPress.

10 active installs v2.0.0 PHP 7.4+ WP 5.6+ Updated Feb 24, 2026
emailemail-formemail-listselectionsharing
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Visitor Analytics and Lead Generation Plugin by Inbound Rocket Safe to Use in 2026?

Generally Safe

Score 100/100

Visitor Analytics and Lead Generation Plugin by Inbound Rocket has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The inbound-rocket plugin version 2.0.0 exhibits a mixed security posture. While it demonstrates good practices in several areas, such as a high percentage of SQL queries using prepared statements and properly escaped output, there are significant concerns regarding its attack surface and potential for vulnerabilities. The presence of 16 AJAX handlers without authentication checks is a critical weakness, creating readily exploitable entry points for attackers. Additionally, the taint analysis revealed 3 flows with unsanitized paths, which, although not classified as critical or high severity in the provided data, represent potential pathways for exploiting user-supplied data if not handled carefully. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign. However, this absence of historical issues should not overshadow the inherent risks identified in the static analysis. The combination of unprotected entry points and unsanitized data flows warrants careful consideration and mitigation.

Key Concerns

  • Unprotected AJAX handlers
  • Taint flows with unsanitized paths
  • Dangerous function: unserialize used
Vulnerabilities
None known

Visitor Analytics and Lead Generation Plugin by Inbound Rocket Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Visitor Analytics and Lead Generation Plugin by Inbound Rocket Code Analysis

Dangerous Functions
1
Raw SQL Queries
31
264 prepared
Unescaped Output
74
1825 escaped
Nonce Checks
38
Capability Checks
26
File Operations
15
External Requests
8
Bundled Libraries
1

Dangerous Functions Found

unserialize$result = unserialize($data, array( 'allowed_classes' => $allowed_classes ));src\Helpers\DataMigration.php:152

Bundled Libraries

Select2

SQL Query Safety

89% prepared295 total queries

Output Escaping

96% escaped1899 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

20 flows3 with unsanitized paths
_inboundrocket_insert_form_submission_legacy (inc\inboundrocket-ajax-functions.php:49)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
16 unprotected

Visitor Analytics and Lead Generation Plugin by Inbound Rocket Attack Surface

Entry Points36
Unprotected16

AJAX Handlers 34

authwp_ajax_inboundrocket_log_pageviewinc\inboundrocket-ajax-functions.php:19
noprivwp_ajax_inboundrocket_log_pageviewinc\inboundrocket-ajax-functions.php:20
authwp_ajax_inboundrocket_insert_leadinc\inboundrocket-ajax-functions.php:32
noprivwp_ajax_inboundrocket_insert_leadinc\inboundrocket-ajax-functions.php:33
authwp_ajax_inboundrocket_insert_form_submissioninc\inboundrocket-ajax-functions.php:375
noprivwp_ajax_inboundrocket_insert_form_submissioninc\inboundrocket-ajax-functions.php:376
authwp_ajax_inboundrocket_check_visitor_statusinc\inboundrocket-ajax-functions.php:387
noprivwp_ajax_inboundrocket_check_visitor_statusinc\inboundrocket-ajax-functions.php:388
authwp_ajax_inboundrocket_get_posts_and_pagesinc\inboundrocket-ajax-functions.php:400
noprivwp_ajax_inboundrocket_get_posts_and_pagesinc\inboundrocket-ajax-functions.php:401
authwp_ajax_inboundrocket_get_form_selectorsinc\inboundrocket-ajax-functions.php:414
noprivwp_ajax_inboundrocket_get_form_selectorsinc\inboundrocket-ajax-functions.php:415
authwp_ajax_aw_delete_api_keyinc\power-ups\aweber-connector.php:67
authwp_ajax_cm_delete_api_keyinc\power-ups\campaign-monitor-connector.php:74
authwp_ajax_click_to_tweet_trackinc\power-ups\click-to-tweet.php:74
noprivwp_ajax_click_to_tweet_trackinc\power-ups\click-to-tweet.php:75
authwp_ajax_mc_delete_api_keyinc\power-ups\mailchimp-connector.php:68
authwp_ajax_pm_delete_api_keyinc\power-ups\postmatic-connector.php:69
authwp_ajax_ir_sb_autocompleteinc\power-ups\scroll-boxes\admin\scroll-boxes-admin.php:43
authwp_ajax_selection_sharer_gettextinc\power-ups\selection-sharer.php:72
noprivwp_ajax_selection_sharer_gettextinc\power-ups\selection-sharer.php:73
authwp_ajax_selection_sharer_trackinc\power-ups\selection-sharer.php:75
noprivwp_ajax_selection_sharer_trackinc\power-ups\selection-sharer.php:76
authwp_ajax_selection_sharer_settingsinc\power-ups\selection-sharer.php:78
noprivwp_ajax_selection_sharer_settingsinc\power-ups\selection-sharer.php:79
authwp_ajax_selection_sharer_shorturlinc\power-ups\selection-sharer.php:81
noprivwp_ajax_selection_sharer_shorturlinc\power-ups\selection-sharer.php:82
authwp_ajax_ir_wbp_autocompleteinc\power-ups\welcome-bar-pro\admin\welcome-bar-admin.php:46
authwp_ajax_welcome_bar-save_dbinc\power-ups\welcome-bar.php:75
noprivwp_ajax_welcome_bar-save_dbinc\power-ups\welcome-bar.php:76
authwp_ajax_ir_wm_autocompleteinc\power-ups\welcome-mat\admin\welcome-mat-admin.php:46
authwp_ajax_send_gdpr_infosrc\Admin\AdminPanel.php:353
authwp_ajax_ir_ec_callbacksrc\Core\Plugin.php:330
noprivwp_ajax_ir_ec_callbacksrc\Core\Plugin.php:331

Shortcodes 2

[clicktotweet] inc\power-ups\click-to-tweet.php:77
[ir_cookies_accepted] inc\power-ups\gdpr-compliance.php:235
WordPress Hooks 87
actionplugins_loadedinbound-rocket.php:111
actionwpmu_new_bloginbound-rocket.php:129
actionwp_dashboard_setupinbound-rocket.php:137
actionadmin_initinbound-rocket.php:147
actionadmin_initinc\backward-compatibility.php:272
actionadmin_noticesinc\backward-compatibility.php:273
actionadmin_footerinc\power-ups\aweber-connector.php:66
actionadmin_footerinc\power-ups\campaign-monitor-connector.php:73
filtertiny_mce_versioninc\power-ups\click-to-tweet\admin\click-to-tweet-admin.php:27
actionadmin_headinc\power-ups\click-to-tweet\admin\click-to-tweet-admin.php:30
filtermce_external_pluginsinc\power-ups\click-to-tweet\admin\click-to-tweet-admin.php:110
filtermce_buttonsinc\power-ups\click-to-tweet\admin\click-to-tweet-admin.php:111
actionwp_enqueue_scriptsinc\power-ups\click-to-tweet.php:70
actionwp_enqueue_scriptsinc\power-ups\exit-intent.php:74
actionwp_footerinc\power-ups\exit-intent.php:76
actioninitinc\power-ups\gdpr-compliance.php:74
actionadmin_initinc\power-ups\gdpr-compliance.php:75
actionadmin_enqueue_scriptsinc\power-ups\gdpr-compliance.php:76
actionwp_enqueue_scriptsinc\power-ups\gdpr-compliance.php:77
actionwp_headinc\power-ups\gdpr-compliance.php:78
actionwp_print_footer_scriptsinc\power-ups\gdpr-compliance.php:79
actionwp_footerinc\power-ups\gdpr-compliance.php:80
filterbody_classinc\power-ups\gdpr-compliance.php:83
actionadmin_footerinc\power-ups\mailchimp-connector.php:67
actioninitinc\power-ups\scroll-boxes\admin\scroll-boxes-admin-functions.php:35
actionadd_meta_boxesinc\power-ups\scroll-boxes\admin\scroll-boxes-admin-functions.php:68
actionsave_postinc\power-ups\scroll-boxes\admin\scroll-boxes-admin-functions.php:176
filtercontent_edit_preinc\power-ups\scroll-boxes\admin\scroll-boxes-admin-functions.php:250
actionadmin_enqueue_scriptsinc\power-ups\scroll-boxes\admin\scroll-boxes-admin.php:37
filterredirect_post_locationinc\power-ups\scroll-boxes\admin\scroll-boxes-admin.php:38
actionload-inbound-rocket_page_inboundrocket_settingsinc\power-ups\scroll-boxes\admin\scroll-boxes-admin.php:40
filterset-screen-optioninc\power-ups\scroll-boxes\admin\scroll-boxes-admin.php:41
actionin_admin_headerinc\power-ups\scroll-boxes\admin\scroll-boxes-admin.php:55
actionin_admin_footerinc\power-ups\scroll-boxes\admin\scroll-boxes-admin.php:56
actionwp_headinc\power-ups\scroll-boxes\scroll-box-class.php:14
actionwp_footerinc\power-ups\scroll-boxes\scroll-box-class.php:15
actionwp_enqueue_scriptsinc\power-ups\scroll-boxes.php:76
actionwpinc\power-ups\scroll-boxes.php:78
actionadmin_enqueue_scriptsinc\power-ups\selection-sharer\admin\selection-sharer-admin.php:27
actionwp_headinc\power-ups\selection-sharer.php:68
actionwp_enqueue_scriptsinc\power-ups\selection-sharer.php:70
actionwp_headinc\power-ups\selection-sharer.php:84
actionadmin_enqueue_scriptsinc\power-ups\welcome-bar\admin\welcome-bar-admin.php:32
actioninitinc\power-ups\welcome-bar-pro\admin\welcome-bar-admin-functions.php:5
actioninitinc\power-ups\welcome-bar-pro\admin\welcome-bar-admin-functions.php:37
actionadd_meta_boxes_ir-welcome-bar-proinc\power-ups\welcome-bar-pro\admin\welcome-bar-admin-functions.php:43
actionsave_postinc\power-ups\welcome-bar-pro\admin\welcome-bar-admin-functions.php:275
filtercontent_edit_preinc\power-ups\welcome-bar-pro\admin\welcome-bar-admin-functions.php:347
actionadmin_enqueue_scriptsinc\power-ups\welcome-bar-pro\admin\welcome-bar-admin.php:38
filterredirect_post_locationinc\power-ups\welcome-bar-pro\admin\welcome-bar-admin.php:39
actionload-inbound-rocket_page_inboundrocket_settingsinc\power-ups\welcome-bar-pro\admin\welcome-bar-admin.php:41
filterset-screen-optioninc\power-ups\welcome-bar-pro\admin\welcome-bar-admin.php:42
actioncurrent_screeninc\power-ups\welcome-bar-pro\admin\welcome-bar-admin.php:44
actionin_admin_headerinc\power-ups\welcome-bar-pro\admin\welcome-bar-admin.php:55
actionin_admin_footerinc\power-ups\welcome-bar-pro\admin\welcome-bar-admin.php:56
actionwp_enqueue_scriptsinc\power-ups\welcome-bar-pro.php:74
actionwp_loadedinc\power-ups\welcome-bar-pro.php:76
actionwp_footerinc\power-ups\welcome-bar-pro.php:81
actionwp_enqueue_scriptsinc\power-ups\welcome-bar.php:70
actionwp_footerinc\power-ups\welcome-bar.php:72
actioninitinc\power-ups\welcome-mat\admin\welcome-mat-admin-functions.php:5
actioninitinc\power-ups\welcome-mat\admin\welcome-mat-admin-functions.php:37
actionadd_meta_boxes_ir-welcome-matinc\power-ups\welcome-mat\admin\welcome-mat-admin-functions.php:43
actionsave_postinc\power-ups\welcome-mat\admin\welcome-mat-admin-functions.php:279
filtercontent_edit_preinc\power-ups\welcome-mat\admin\welcome-mat-admin-functions.php:351
actionadmin_enqueue_scriptsinc\power-ups\welcome-mat\admin\welcome-mat-admin.php:38
filterredirect_post_locationinc\power-ups\welcome-mat\admin\welcome-mat-admin.php:39
actionload-inbound-rocket_page_inboundrocket_settingsinc\power-ups\welcome-mat\admin\welcome-mat-admin.php:41
filterset-screen-optioninc\power-ups\welcome-mat\admin\welcome-mat-admin.php:42
actioncurrent_screeninc\power-ups\welcome-mat\admin\welcome-mat-admin.php:44
actionin_admin_headerinc\power-ups\welcome-mat\admin\welcome-mat-admin.php:55
actionin_admin_footerinc\power-ups\welcome-mat\admin\welcome-mat-admin.php:56
actionwp_enqueue_scriptsinc\power-ups\welcome-mat.php:74
actionwp_loadedinc\power-ups\welcome-mat.php:76
actionwp_footerinc\power-ups\welcome-mat.php:81
actionadmin_menusrc\Admin\AdminPanel.php:350
actionadmin_initsrc\Admin\AdminPanel.php:351
actionadmin_print_stylessrc\Admin\AdminPanel.php:355
actionadmin_enqueue_scriptssrc\Admin\AdminPanel.php:356
filterplugin_action_linkssrc\Admin\AdminPanel.php:358
filterwp_privacy_personal_data_exporterssrc\Admin\AdminPanel.php:359
actionadmin_footersrc\Admin\AdminPanel.php:364
actionadmin_footersrc\Admin\Dashboard\Stats.php:369
actionadmin_footersrc\Admin\Dashboard\Stats.php:382
actionadmin_bar_menusrc\Core\Plugin.php:315
actionlogin_enqueue_scriptssrc\Core\Plugin.php:324
actionwp_enqueue_scriptssrc\Core\Plugin.php:326
Maintenance & Trust

Visitor Analytics and Lead Generation Plugin by Inbound Rocket Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 24, 2026
PHP min version7.4
Downloads9K

Community Trust

Rating82/100
Number of ratings9
Active installs10
Developer Profile

Visitor Analytics and Lead Generation Plugin by Inbound Rocket Developer Profile

inboundrocket

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Visitor Analytics and Lead Generation Plugin by Inbound Rocket

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/inbound-rocket/css/style.css/wp-content/plugins/inbound-rocket/js/main.js/wp-content/plugins/inbound-rocket/js/admin.js/wp-content/plugins/inbound-rocket/css/admin.css
Script Paths
/wp-content/plugins/inbound-rocket/js/main.js/wp-content/plugins/inbound-rocket/js/admin.js
Version Parameters
inbound-rocket/style.css?ver=inbound-rocket/main.js?ver=inbound-rocket/admin.js?ver=inbound-rocket/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
ir-lead-statsinboundrocket-widget
HTML Comments
<!-- INBOUNDROCKET START --><!-- INBOUNDROCKET END --><!-- Leads are displayed here --><!-- Widget starts here -->+1 more
Data Attributes
data-inboundrocket-lead-iddata-inboundrocket-campaign-id
JS Globals
window.InboundRocketvar InboundRocket = {
REST Endpoints
/wp-json/inboundrocket/v1/leads/wp-json/inboundrocket/v1/settings
Shortcode Output
[inbound_rocket_form][inbound_rocket_analytics][inbound_rocket_tracking]
FAQ

Frequently Asked Questions about Visitor Analytics and Lead Generation Plugin by Inbound Rocket