
Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More Security & Risk Analysis
wordpress.org/plugins/integrate-with-hubspot-crmConnect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with HubSpot CRM.
Is Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More Safe to Use in 2026?
Generally Safe
Score 100/100Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "integrate-with-hubspot-crm" plugin version 1.0.13 exhibits a generally strong security posture, with several positive indicators. Notably, there are no known CVEs, indicating a history of responsible vulnerability management. The static analysis reveals a well-implemented approach to handling external requests and output, with a high percentage of properly escaped outputs and a significant use of prepared statements for SQL queries. Furthermore, the plugin demonstrates good practice by implementing nonce checks on its AJAX handlers, and there are no apparent file operations or dangerous functions. This suggests a developer who is mindful of common security pitfalls.
However, the analysis does highlight areas of concern. The taint analysis reveals three high-severity flows with unsanitized paths, and a total of seven flows with unsanitized paths. While there are no directly exploitable critical vulnerabilities indicated, these high-severity taint flows represent potential pathways for attackers to introduce malicious data or code if not properly handled downstream. The absence of capability checks on the 4 AJAX handlers is another significant concern; while nonce checks are present, the lack of capability checks means that any authenticated user, regardless of their role or permissions, could potentially trigger these AJAX actions. This significantly expands the attack surface for these handlers.
In conclusion, the plugin benefits from a clean vulnerability history and good practices in output escaping and SQL query preparation. However, the presence of high-severity unsanitized paths and the critical omission of capability checks on AJAX handlers introduce notable risks that should be addressed to ensure a more robust security profile.
Key Concerns
- High severity taint flows
- Unsanitized paths in taint flows
- AJAX handlers without capability checks
Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More Security Vulnerabilities
Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More Attack Surface
AJAX Handlers 4
WordPress Hooks 17
Maintenance & Trust
Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More Maintenance & Trust
Maintenance Signals
Community Trust
Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More Alternatives
Integration for Mailchimp – Contact Form 7, WPForms, Elementor, Gravity Forms and More
integrate-with-mailchimp
Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with Mailchimp.
Integration for Zoho Campaigns – Contact Form 7, WPForms, Elementor, Gravity Forms and More
integrate-with-zoho-campaigns
Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with Zoho Campaigns.
Integration for Zoho Desk – Contact Form 7, WPForms, Elementor, Gravity Forms and More
integrate-with-zoho-desk
Connect Contact Form 7, WPForms, Elementor Forms, Gravity Forms, and more form submissions with Zoho Desk.
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-hubspot
Send Contact Form 7, WPForms, Elementor, Ninja Forms, WPforms, Elementor, Ninja Forms, Contact Form Entries Plugin and many other contact form submiss …
Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More Developer Profile
8 plugins · 110 total installs
How We Detect Integration for HubSpot – Contact Form 7, WPForms, Elementor, Gravity Forms and More
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/integrate-with-hubspot-crm/includes/css/accounts-tab.css/wp-content/plugins/integrate-with-hubspot-crm/includes/css/other-plugins.css/wp-content/plugins/integrate-with-hubspot-crm/includes/js/accounts-tab.js/wp-content/plugins/integrate-with-hubspot-crm/includes/js/other-plugins.js/wp-content/plugins/integrate-with-hubspot-crm/includes/js/accounts-tab.js/wp-content/plugins/integrate-with-hubspot-crm/includes/js/other-plugins.jsintegrate-with-hubspot-crm/includes/css/accounts-tab.css?ver=integrate-with-hubspot-crm/includes/css/other-plugins.css?ver=integrate-with-hubspot-crm/includes/js/accounts-tab.js?ver=integrate-with-hubspot-crm/includes/js/other-plugins.js?ver=HTML / DOM Fingerprints
iafwhc-tab-contentiafwhc-span-headeriafwhc-help-icon-wrapperiafwhc-help-iconiafwhc-help-tooltipiafwhc-auth-popup-overlayiafwhc-auth-popup-contentiafwhc-auth-closedata-tabiafwhc_accountDBInstance