Integration of BenchmarkEmail CRM For Elementor Pro Form Security & Risk Analysis

wordpress.org/plugins/integrate-benchmarkemail-crm-elementor

Benchmark Email Integration for Elementor Pro allow you to send your Elementor Pro Form Widget entries directly to your Benchmark Email account

10 active installs v1.0.0 PHP 5.6+ WP 4.7+ Updated Aug 9, 2020
benchmarkemailbenchmarkemail-crmbenchmarkemail-elementorelementor-benchmark-emailelementor-form-crm
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Integration of BenchmarkEmail CRM For Elementor Pro Form Safe to Use in 2026?

Generally Safe

Score 85/100

Integration of BenchmarkEmail CRM For Elementor Pro Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The plugin "integrate-benchmarkemail-crm-elementor" v1.0.0 exhibits a mixed security posture. On the positive side, the code analysis reveals no use of dangerous functions, all SQL queries are prepared, and a high percentage of output is properly escaped. There are also no known past vulnerabilities recorded, suggesting a potentially stable history.

However, significant concerns arise from the attack surface analysis. The presence of one AJAX handler without any authentication or capability checks is a critical weakness. This unauthenticated entry point could be exploited by attackers to perform unintended actions. The absence of nonce checks on this handler further exacerbates the risk, making it susceptible to Cross-Site Request Forgery (CSRF) attacks. While taint analysis found no issues, this is likely due to the limited scope of the analysis or lack of complex data flows.

In conclusion, while the plugin demonstrates good practices in areas like SQL querying and output escaping, the unauthenticated AJAX endpoint presents a clear and exploitable vulnerability. The lack of any recorded vulnerabilities in its history might be due to its limited exposure or recent release, but it should not instill a false sense of security given the identified flaw. The plugin requires immediate attention to secure its entry points.

Key Concerns

  • Unprotected AJAX handler found
  • Missing nonce checks on AJAX
  • Missing capability checks on AJAX
  • Potential for unescaped output
Vulnerabilities
None known

Integration of BenchmarkEmail CRM For Elementor Pro Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Integration of BenchmarkEmail CRM For Elementor Pro Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
11 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

85% escaped13 total outputs
Attack Surface
1 unprotected

Integration of BenchmarkEmail CRM For Elementor Pro Form Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_get_benchmarkemail_custom_fieldsapp\class-app.php:40
WordPress Hooks 6
actionadmin_initapp\class-app.php:36
actionelementor_pro/initapp\class-app.php:37
actionadmin_menuapp\class-app.php:38
actionelementor/editor/after_enqueue_scriptsapp\class-app.php:39
actionadmin_initelementor-benchmarkemail-addon.php:23
actionadmin_noticeselementor-benchmarkemail-addon.php:26
Maintenance & Trust

Integration of BenchmarkEmail CRM For Elementor Pro Form Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedAug 9, 2020
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Integration of BenchmarkEmail CRM For Elementor Pro Form Alternatives

No alternatives data available yet.

Developer Profile

Integration of BenchmarkEmail CRM For Elementor Pro Form Developer Profile

WiserSteps

2 plugins · 210 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Integration of BenchmarkEmail CRM For Elementor Pro Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integrate-benchmarkemail-crm-elementor/app/assets/js/elementor-benchmarkemail-addon.js
Script Paths
/wp-content/plugins/integrate-benchmarkemail-crm-elementor/app/assets/js/elementor-benchmarkemail-addon.js
Version Parameters
integrate-benchmarkemail-crm-elementor/app/assets/js/elementor-benchmarkemail-addon.js?ver=

HTML / DOM Fingerprints

JS Globals
php_vars
REST Endpoints
/wp-json/elementor-benchmarkemail-addon/v1/get_benchmarkemail_custom_fields
FAQ

Frequently Asked Questions about Integration of BenchmarkEmail CRM For Elementor Pro Form