RD Station Security & Risk Analysis

wordpress.org/plugins/integracao-rd-station

Integrate your contact forms with RD Station Marketing

20K active installs v5.6.0 PHP + WP 4.7+ Updated Aug 11, 2025
contact-formformsintegrationsrd-stationresultados-digitais
98
A · Safe
CVEs total2
Unpatched0
Last CVESep 4, 2024
Safety Verdict

Is RD Station Safe to Use in 2026?

Generally Safe

Score 98/100

RD Station has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Sep 4, 2024Updated 7mo ago
Risk Assessment

The static analysis of the 'integracao-rd-station' plugin v5.6.0 reveals a generally good security posture. The plugin demonstrates strong adherence to best practices by implementing proper nonce checks for all identified AJAX entry points and utilizing prepared statements for all SQL queries. Furthermore, all identified output points are correctly escaped, mitigating the risk of cross-site scripting vulnerabilities stemming from the code itself. The absence of critical or high-severity taint analysis findings is also a positive indicator.

However, the plugin's vulnerability history presents a significant concern. Despite the current version having no unpatched vulnerabilities, the presence of two known CVEs, including a high and a medium severity vulnerability, indicates a past tendency towards exploitable weaknesses. The common vulnerability types (XSS and CSRF) are particularly relevant as they often exploit user interactions or input handling, even if current static analysis doesn't reveal them. The fact that a vulnerability was reported very recently (September 4, 2024) suggests ongoing security challenges with this plugin.

In conclusion, while the code analysis for v5.6.0 is reassuring, the historical vulnerability data cannot be ignored. The plugin has demonstrated a propensity for XSS and CSRF issues in the past. Users should exercise caution and remain vigilant for future updates, as the plugin's historical security record suggests a need for ongoing scrutiny despite the current version's positive static analysis results. The limited number of capability checks (2) for 10 AJAX handlers also warrants further investigation to ensure all actions are appropriately authorized.

Key Concerns

  • Historical vulnerabilities (1 High, 1 Medium)
  • Limited capability checks for AJAX handlers
Vulnerabilities
2

RD Station Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2024-6894medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

RD Station <= 5.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 4, 2024 Patched in 5.4.0 (2d)
CVE-2022-38139high · 8.8Cross-Site Request Forgery (CSRF)

RD Station <= 5.2.0 - Cross-Site Request Forgery to Plugin Settings Update

Sep 11, 2022 Patched in 5.2.1 (499d)
Code Analysis
Analyzed Mar 16, 2026

RD Station Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
61 escaped
Nonce Checks
10
Capability Checks
2
File Operations
6
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped61 total outputs
Attack Surface

RD Station Attack Surface

Entry Points10
Unprotected0

AJAX Handlers 10

authwp_ajax_rdsm-custom-fieldsincludes\events\rdsm_integration_form_changed.php:10
authwp_ajax_rdsm-woocommerce-fieldsincludes\events\rdsm_integration_form_woocommerce.php:10
authwp_ajax_rdsm-log-fileincludes\events\rdsm_log_file.php:9
authwp_ajax_rdsm-clear-log-fileincludes\events\rdsm_log_file.php:10
authwp_ajax_rdsm_get_log_by_filterincludes\events\rdsm_log_file.php:13
authwp_ajax_rd-persist-tokensincludes\events\rdsm_oauth_connected.php:8
authwp_ajax_rd-persist-legacy-tokensincludes\events\rdsm_oauth_connected.php:9
authwp_ajax_rdsm-disconnect-oauthincludes\events\rdsm_oauth_disconnected.php:7
authwp_ajax_rdsm-authorization-checkincludes\events\rdsm_settings_page_loaded.php:8
authwp_ajax_rdsm-update-tracking-code-statusincludes\events\rdsm_tracking_status_updated.php:10
WordPress Hooks 11
actionadmin_initincludes\events\rdsm_admin_initialized.php:13
actionadmin_footerincludes\events\rdsm_settings_page_loaded.php:9
actionwp_footerincludes\events\rdsm_site_initialized.php:14
actionadd_meta_boxesmetaboxes\RD_Metabox.php:9
actionsave_postmetaboxes\RD_Metabox.php:10
actionadmin_enqueue_scriptsrdsm_assets_loader.php:9
actionadmin_enqueue_scriptsrdsm_assets_loader.php:10
actionadmin_enqueue_scriptsrdsm_assets_loader.php:11
actionadmin_enqueue_scriptsrdsm_assets_loader.php:12
actioninitrd_custom_post_type.php:15
actionadmin_menusettings\settings_menu.php:3
Maintenance & Trust

RD Station Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 11, 2025
PHP min version
Downloads364K

Community Trust

Rating60/100
Number of ratings7
Active installs20K
Developer Profile

RD Station Developer Profile

filipenasc

1 plugin · 20K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
251 days
View full developer profile
Detection Fingerprints

How We Detect RD Station

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integracao-rd-station/assets/styles/admin.css/wp-content/plugins/integracao-rd-station/assets/js/general_settings.js/wp-content/plugins/integracao-rd-station/assets/js/tracking_code.js/wp-content/plugins/integracao-rd-station/assets/js/authorization.js/wp-content/plugins/integracao-rd-station/assets/js/woocommerce_fields.js/wp-content/plugins/integracao-rd-station/assets/js/log_file.js/wp-content/plugins/integracao-rd-station/assets/js/custom_fields.js
Script Paths
/wp-content/plugins/integracao-rd-station/includes/events/rdsm_site_initialized.php
Version Parameters
integracao-rd-station/assets/styles/admin.css?ver=integracao-rd-station/assets/js/general_settings.js?ver=integracao-rd-station/assets/js/tracking_code.js?ver=integracao-rd-station/assets/js/authorization.js?ver=integracao-rd-station/assets/js/woocommerce_fields.js?ver=integracao-rd-station/assets/js/log_file.js?ver=integracao-rd-station/assets/js/custom_fields.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-rd-form-nonce
JS Globals
rdsm_settings_page
REST Endpoints
/wp-json/wp/v2/wp_block
FAQ

Frequently Asked Questions about RD Station