Insert Pipefy Form Launcher Security & Risk Analysis

wordpress.org/plugins/insert-pipefy-form-launcher

Tickets, leads, questions... basically anything from your WordPress website to Pipefy in seconds.

10 active installs v1.0.0 PHP + WP 4.0+ Updated Aug 15, 2020
contact-formformpipefypublic-formtemplate
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Insert Pipefy Form Launcher Safe to Use in 2026?

Generally Safe

Score 85/100

Insert Pipefy Form Launcher has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The 'insert-pipefy-form-launcher' plugin version 1.0.0 exhibits a strong security posture based on the provided static analysis. There are no identified dangerous functions, external HTTP requests, file operations, or SQL queries not using prepared statements. All identified output operations are properly escaped, indicating good practices in preventing cross-site scripting (XSS) vulnerabilities. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface, and importantly, all potential entry points that do exist are not explicitly noted as unprotected.

However, the taint analysis reveals two flows with unsanitized paths. While classified as neither critical nor high severity, these unsanitized paths represent potential weaknesses that could be exploited if the data flowing through them were to originate from untrusted sources and be used in sensitive operations. The vulnerability history is entirely clean, with no known CVEs, which is a positive indicator. Nevertheless, the presence of these unsanitized flows, despite the lack of immediate critical risk, warrants attention as they could become a vector for vulnerabilities in future updates or under specific exploitation scenarios.

In conclusion, the plugin demonstrates a solid foundation with excellent practices in SQL and output handling, coupled with a minimal attack surface and a clean vulnerability history. The primary concern lies with the two identified taint flows with unsanitized paths. While not currently rated as critical, these are the most significant areas for improvement to ensure robust security.

Key Concerns

  • Flows with unsanitized paths
Vulnerabilities
None known

Insert Pipefy Form Launcher Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Insert Pipefy Form Launcher Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Insert Pipefy Form Launcher Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
25 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped25 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ipfl_add_form_admin_page (pipefy-launcher.php:29)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Insert Pipefy Form Launcher Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionwp_footerpipefy-launcher-frontend.php:4
actionwp_enqueue_scriptspipefy-launcher-frontend.php:37
actionwp_enqueue_scriptspipefy-launcher-frontend.php:44
actionadmin_menupipefy-launcher.php:22
actionadmin_enqueue_scriptspipefy-launcher.php:64
Maintenance & Trust

Insert Pipefy Form Launcher Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 15, 2020
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Insert Pipefy Form Launcher Developer Profile

thiagomatsunaga

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Insert Pipefy Form Launcher

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/insert-pipefy-form-launcher/assets/css/frontend.css/wp-content/plugins/insert-pipefy-form-launcher/assets/js/frontend.js
Script Paths
/wp-content/plugins/insert-pipefy-form-launcher/assets/js/backend.js
Version Parameters
insert-pipefy-form-launcher/assets/js/backend.js?ver=insert-pipefy-form-launcher/assets/css/frontend.css?ver=insert-pipefy-form-launcher/assets/js/frontend.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Insert Pipefy Form Launcher