
RD Station Security & Risk Analysis
wordpress.org/plugins/integracao-rd-stationIntegrate your contact forms with RD Station Marketing
Is RD Station Safe to Use in 2026?
Generally Safe
Score 98/100RD Station has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the 'integracao-rd-station' plugin v5.6.0 reveals a generally good security posture. The plugin demonstrates strong adherence to best practices by implementing proper nonce checks for all identified AJAX entry points and utilizing prepared statements for all SQL queries. Furthermore, all identified output points are correctly escaped, mitigating the risk of cross-site scripting vulnerabilities stemming from the code itself. The absence of critical or high-severity taint analysis findings is also a positive indicator.
However, the plugin's vulnerability history presents a significant concern. Despite the current version having no unpatched vulnerabilities, the presence of two known CVEs, including a high and a medium severity vulnerability, indicates a past tendency towards exploitable weaknesses. The common vulnerability types (XSS and CSRF) are particularly relevant as they often exploit user interactions or input handling, even if current static analysis doesn't reveal them. The fact that a vulnerability was reported very recently (September 4, 2024) suggests ongoing security challenges with this plugin.
In conclusion, while the code analysis for v5.6.0 is reassuring, the historical vulnerability data cannot be ignored. The plugin has demonstrated a propensity for XSS and CSRF issues in the past. Users should exercise caution and remain vigilant for future updates, as the plugin's historical security record suggests a need for ongoing scrutiny despite the current version's positive static analysis results. The limited number of capability checks (2) for 10 AJAX handlers also warrants further investigation to ensure all actions are appropriately authorized.
Key Concerns
- Historical vulnerabilities (1 High, 1 Medium)
- Limited capability checks for AJAX handlers
RD Station Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
RD Station <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
RD Station <= 5.2.0 - Cross-Site Request Forgery to Plugin Settings Update
RD Station Code Analysis
Output Escaping
RD Station Attack Surface
AJAX Handlers 10
WordPress Hooks 11
Maintenance & Trust
RD Station Maintenance & Trust
Maintenance Signals
Community Trust
RD Station Alternatives
GSheetConnector for CF7 – Connect Contact Form 7 to Google Sheets and Send Form Submissions in Real Time
cf7-google-sheets-connector
Send your Contact Form 7 data directly to your Google Sheets spreadsheet.
Caldera Forms Google Sheets Connector
gsheetconnector-caldera-forms
Send your Caldera Forms data directly to your Google Sheets spreadsheet.
CF7 LACRM Connector
lacrm-connector-for-contact-form7
Send your Contact Form 7 data directly to your Less Annoying CRM account.
SA Integrations For Google Sheets
sa-integrations-for-google-sheets
This plugin connects your WordPress website with Google Sheets, enabling automatic synchronization of form submissions and WooCommerce order data.
Gsheet Contact Addons & ShortCode
shortcode-addons-for-google-sheet-api
Send your Contact Form 7 data directly to your Google Sheets spreadsheet API.
RD Station Developer Profile
1 plugin · 20K total installs
How We Detect RD Station
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/integracao-rd-station/assets/styles/admin.css/wp-content/plugins/integracao-rd-station/assets/js/general_settings.js/wp-content/plugins/integracao-rd-station/assets/js/tracking_code.js/wp-content/plugins/integracao-rd-station/assets/js/authorization.js/wp-content/plugins/integracao-rd-station/assets/js/woocommerce_fields.js/wp-content/plugins/integracao-rd-station/assets/js/log_file.js/wp-content/plugins/integracao-rd-station/assets/js/custom_fields.js/wp-content/plugins/integracao-rd-station/includes/events/rdsm_site_initialized.phpintegracao-rd-station/assets/styles/admin.css?ver=integracao-rd-station/assets/js/general_settings.js?ver=integracao-rd-station/assets/js/tracking_code.js?ver=integracao-rd-station/assets/js/authorization.js?ver=integracao-rd-station/assets/js/woocommerce_fields.js?ver=integracao-rd-station/assets/js/log_file.js?ver=integracao-rd-station/assets/js/custom_fields.js?ver=HTML / DOM Fingerprints
data-rd-form-noncerdsm_settings_page/wp-json/wp/v2/wp_block