Infusionsoft Web Form JavaScript Security & Risk Analysis

wordpress.org/plugins/infusionsoft-web-form-javascript

Easily add Infusionsoft web forms to your posts and pages. Automatically converts JavaScript to WordPress-friendly shortcodes.

50 active installs v1.1.1 PHP + WP 2.7+ Updated Dec 18, 2014
infusionsoftjavascriptweb-formswebformwebforms
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEMar 31, 2025
Safety Verdict

Is Infusionsoft Web Form JavaScript Safe to Use in 2026?

Use With Caution

Score 64/100

Infusionsoft Web Form JavaScript has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Mar 31, 2025Updated 11yr ago
Risk Assessment

The plugin "infusionsoft-web-form-javascript" v1.1.1 exhibits a mixed security posture. While the static analysis shows a very limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, no direct SQL queries or file operations, there are significant concerns regarding output escaping and a known vulnerability.

The static analysis reveals that only 25% of the identified output points are properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. This is further corroborated by the vulnerability history, which shows a medium severity CVE related to 'Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')'. The existence of a currently unpatched medium severity vulnerability is a critical weakness that needs immediate attention.

While the absence of common attack vectors like direct SQL injection or insecure file operations is positive, the unpatched XSS vulnerability and the poor output escaping practices present a tangible risk to users. The plugin's vulnerability history suggests a pattern of potential security flaws, necessitating a cautious approach and prompt patching of identified vulnerabilities.

Key Concerns

  • Unpatched Medium severity CVE
  • Poor output escaping (75% unescaped)
Vulnerabilities
1 published

Infusionsoft Web Form JavaScript Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31629medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Infusionsoft Web Form JavaScript <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 31, 2025Unpatched
Version History

Infusionsoft Web Form JavaScript Release Timeline

v1.1.1Current1 CVE
v1.1.01 CVE
Code Analysis
Analyzed Apr 16, 2026

Infusionsoft Web Form JavaScript Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
1 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

25% escaped4 total outputs
Attack Surface

Infusionsoft Web Form JavaScript Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterwp_insert_post_datanovaksolutions-infusionsoft-javascript.php:46
filterplugin_action_linksnovaksolutions-infusionsoft-javascript.php:57
actionadmin_menunovaksolutions-infusionsoft-javascript.php:67
actionadmin_initnovaksolutions-infusionsoft-javascript.php:123
Maintenance & Trust

Infusionsoft Web Form JavaScript Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedDec 18, 2014
PHP min version
Downloads5K

Community Trust

Rating80/100
Number of ratings4
Active installs50
Developer Profile

Infusionsoft Web Form JavaScript Developer Profile

Jacob Allred

6 plugins · 380 total installs

81
trust score
Avg Security Score
82/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Infusionsoft Web Form JavaScript

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/infusionsoft-web-form-javascript/novaksolutions-infusionsoft-javascript.php

HTML / DOM Fingerprints

CSS Classes
javascript-container
Data Attributes
data-src
Shortcode Output
[javascript[javascript src=
FAQ

Frequently Asked Questions about Infusionsoft Web Form JavaScript