
Integration of BenchmarkEmail CRM For Elementor Pro Form Security & Risk Analysis
wordpress.org/plugins/integrate-benchmarkemail-crm-elementorBenchmark Email Integration for Elementor Pro allow you to send your Elementor Pro Form Widget entries directly to your Benchmark Email account
Is Integration of BenchmarkEmail CRM For Elementor Pro Form Safe to Use in 2026?
Generally Safe
Score 85/100Integration of BenchmarkEmail CRM For Elementor Pro Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "integrate-benchmarkemail-crm-elementor" v1.0.0 exhibits a mixed security posture. On the positive side, the code analysis reveals no use of dangerous functions, all SQL queries are prepared, and a high percentage of output is properly escaped. There are also no known past vulnerabilities recorded, suggesting a potentially stable history.
However, significant concerns arise from the attack surface analysis. The presence of one AJAX handler without any authentication or capability checks is a critical weakness. This unauthenticated entry point could be exploited by attackers to perform unintended actions. The absence of nonce checks on this handler further exacerbates the risk, making it susceptible to Cross-Site Request Forgery (CSRF) attacks. While taint analysis found no issues, this is likely due to the limited scope of the analysis or lack of complex data flows.
In conclusion, while the plugin demonstrates good practices in areas like SQL querying and output escaping, the unauthenticated AJAX endpoint presents a clear and exploitable vulnerability. The lack of any recorded vulnerabilities in its history might be due to its limited exposure or recent release, but it should not instill a false sense of security given the identified flaw. The plugin requires immediate attention to secure its entry points.
Key Concerns
- Unprotected AJAX handler found
- Missing nonce checks on AJAX
- Missing capability checks on AJAX
- Potential for unescaped output
Integration of BenchmarkEmail CRM For Elementor Pro Form Security Vulnerabilities
Integration of BenchmarkEmail CRM For Elementor Pro Form Code Analysis
Output Escaping
Integration of BenchmarkEmail CRM For Elementor Pro Form Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
Integration of BenchmarkEmail CRM For Elementor Pro Form Maintenance & Trust
Maintenance Signals
Community Trust
Integration of BenchmarkEmail CRM For Elementor Pro Form Alternatives
No alternatives data available yet.
Integration of BenchmarkEmail CRM For Elementor Pro Form Developer Profile
2 plugins · 210 total installs
How We Detect Integration of BenchmarkEmail CRM For Elementor Pro Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/integrate-benchmarkemail-crm-elementor/app/assets/js/elementor-benchmarkemail-addon.js/wp-content/plugins/integrate-benchmarkemail-crm-elementor/app/assets/js/elementor-benchmarkemail-addon.jsintegrate-benchmarkemail-crm-elementor/app/assets/js/elementor-benchmarkemail-addon.js?ver=HTML / DOM Fingerprints
php_vars/wp-json/elementor-benchmarkemail-addon/v1/get_benchmarkemail_custom_fields