
Visitor Analytics and Lead Generation Plugin by Inbound Rocket Security & Risk Analysis
wordpress.org/plugins/inbound-rocketThe easiest way to double your leads. Inbound Rocket is an easy-to-use marketing automation and lead tracking plugin for WordPress.
Is Visitor Analytics and Lead Generation Plugin by Inbound Rocket Safe to Use in 2026?
Generally Safe
Score 100/100Visitor Analytics and Lead Generation Plugin by Inbound Rocket has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The inbound-rocket plugin version 2.0.0 exhibits a mixed security posture. While it demonstrates good practices in several areas, such as a high percentage of SQL queries using prepared statements and properly escaped output, there are significant concerns regarding its attack surface and potential for vulnerabilities. The presence of 16 AJAX handlers without authentication checks is a critical weakness, creating readily exploitable entry points for attackers. Additionally, the taint analysis revealed 3 flows with unsanitized paths, which, although not classified as critical or high severity in the provided data, represent potential pathways for exploiting user-supplied data if not handled carefully. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign. However, this absence of historical issues should not overshadow the inherent risks identified in the static analysis. The combination of unprotected entry points and unsanitized data flows warrants careful consideration and mitigation.
Key Concerns
- Unprotected AJAX handlers
- Taint flows with unsanitized paths
- Dangerous function: unserialize used
Visitor Analytics and Lead Generation Plugin by Inbound Rocket Security Vulnerabilities
Visitor Analytics and Lead Generation Plugin by Inbound Rocket Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Visitor Analytics and Lead Generation Plugin by Inbound Rocket Attack Surface
AJAX Handlers 34
Shortcodes 2
WordPress Hooks 87
Maintenance & Trust
Visitor Analytics and Lead Generation Plugin by Inbound Rocket Maintenance & Trust
Maintenance Signals
Community Trust
Visitor Analytics and Lead Generation Plugin by Inbound Rocket Alternatives
Social Offers
social-offers-and-digital-downloads
Offer Social Coupons and Rewards for Email list subscribers.
HTML Forms – Simple WordPress Forms Plugin
html-forms
A simpler, faster, and smarter WordPress forms plugin.
WPZOOM Forms – Drag & Drop Contact Form Builder for WordPress
wpzoom-forms
Drag & drop contact form builder for WordPress. Create contact forms, custom forms, email forms with spam protection. Works with Elementor, shortcodes
YITH WooCommerce Waitlist
yith-woocommerce-waiting-list
This plugin enables registered users to request an email notification when an out-of-stock product comes back into stock.
Contact Form Widget
new-contact-form-widget
Create contact forms with query table management. Simple setup, secure submissions, and easy customization for your site.
Visitor Analytics and Lead Generation Plugin by Inbound Rocket Developer Profile
1 plugin · 10 total installs
How We Detect Visitor Analytics and Lead Generation Plugin by Inbound Rocket
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/inbound-rocket/css/style.css/wp-content/plugins/inbound-rocket/js/main.js/wp-content/plugins/inbound-rocket/js/admin.js/wp-content/plugins/inbound-rocket/css/admin.css/wp-content/plugins/inbound-rocket/js/main.js/wp-content/plugins/inbound-rocket/js/admin.jsinbound-rocket/style.css?ver=inbound-rocket/main.js?ver=inbound-rocket/admin.js?ver=inbound-rocket/admin.css?ver=HTML / DOM Fingerprints
ir-lead-statsinboundrocket-widget<!-- INBOUNDROCKET START --><!-- INBOUNDROCKET END --><!-- Leads are displayed here --><!-- Widget starts here -->+1 moredata-inboundrocket-lead-iddata-inboundrocket-campaign-idwindow.InboundRocketvar InboundRocket = {/wp-json/inboundrocket/v1/leads/wp-json/inboundrocket/v1/settings[inbound_rocket_form][inbound_rocket_analytics][inbound_rocket_tracking]