Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Security & Risk Analysis

wordpress.org/plugins/integration-for-contact-form-7-and-pipedrive

Send Contact Form 7, WPForms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to Pipedrive.

1K active installs v1.2.6 PHP 5.3+ WP 3.8+ Updated Mar 22, 2026
contact-form-7-pipedrivecontact-form-7-pipedrive-integrationelementor-forms-pipedriveninja-forms-pipedrivewpforms-pipedrive
93
A · Safe
CVEs total3
Unpatched0
Last CVEJul 18, 2025
Safety Verdict

Is Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Safe to Use in 2026?

Generally Safe

Score 93/100

Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

3 known CVEsLast CVE: Jul 18, 2025Updated 1mo ago
Risk Assessment

The plugin 'integration-for-contact-form-7-and-pipedrive' version 1.2.5 exhibits a mixed security posture. On one hand, the static analysis reveals a promising lack of direct entry points like AJAX handlers, REST API routes, and shortcodes that are unprotected by authentication. This suggests a relatively contained attack surface. Furthermore, the presence of a good percentage of prepared statements for SQL queries and a decent rate of output escaping are positive indicators of secure coding practices. However, the vulnerability history is a significant concern. With three known CVEs, including a past critical vulnerability and two medium severity issues, the plugin has a track record of security flaws. The types of past vulnerabilities (Deserialization, CSRF, XSS) indicate potential for serious compromise if similar issues are present or reoccur.

While the current static analysis shows no critical or high severity taint flows and a low number of file operations and external HTTP requests, the historical vulnerability data cannot be ignored. The past critical vulnerability and the presence of bundled libraries (Select2) which might be outdated or vulnerable warrant careful consideration. The plugin shows efforts towards security with nonce and capability checks, but the persistent occurrence of security flaws in its history is a red flag. The plugin's overall security is therefore tempered by its past performance, suggesting that users should remain vigilant and ensure they are always running the latest patched version, though currently there are no unpatched CVEs.

Key Concerns

  • History of critical vulnerability
  • History of medium vulnerabilities
  • Bundled libraries (Select2)
Vulnerabilities
3 published

Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Critical
1
Medium
2

3 total CVEs

CVE-2025-7696critical · 9.8Deserialization of Untrusted Data

Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.2.3 - Unauthenticated PHP Object Injection via verify_field_val Function

Jul 18, 2025 Patched in 1.2.4 (1d)
CVE-2024-34817medium · 4.3Cross-Site Request Forgery (CSRF)

Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.2.0 - Cross-Site Request Forgery

May 9, 2024 Patched in 1.2.1 (7d)
WF-cc1e9778-2860-4e3c-a2e4-28f10d585fed-integration-for-contact-form-7-and-pipedrivemedium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting

Aug 26, 2021 Patched in 1.1.1 (880d)
Code Analysis
Analyzed Mar 16, 2026

Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
8
25 prepared
Unescaped Output
92
331 escaped
Nonce Checks
17
Capability Checks
23
File Operations
2
External Requests
2
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

76% prepared33 total queries

Output Escaping

78% escaped423 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
settings_page (includes\plugin-pages.php:1458)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 39
actionvx_cf_add_meta_boxincludes\crmperks-cf.php:10
actioncfx_add_meta_boxincludes\plugin-pages.php:35
actioncfx_form_entry_updatedincludes\plugin-pages.php:36
actioncfx_form_post_note_addedincludes\plugin-pages.php:37
actioncfx_form_pre_note_deletedincludes\plugin-pages.php:38
actioncfx_form_pre_trash_leadsincludes\plugin-pages.php:39
actioncfx_form_pre_restore_leadsincludes\plugin-pages.php:40
filteradmin_menuincludes\plugin-pages.php:52
filtervx_cf_meta_boxes_rightincludes\plugin-pages.php:53
actionadmin_noticesincludes\plugin-pages.php:54
filterplugin_action_linksincludes\plugin-pages.php:55
actionvxcf_entry_submit_btnincludes\plugin-pages.php:56
actionvx_cf7_post_note_addedincludes\plugin-pages.php:58
actionvx_cf7_pre_note_deletedincludes\plugin-pages.php:59
actionvx_cf7_pre_trash_leadsincludes\plugin-pages.php:60
actionvx_cf7_pre_restore_leadsincludes\plugin-pages.php:61
actionvx_cf7_entry_updatedincludes\plugin-pages.php:62
actionvx_contact_post_note_addedincludes\plugin-pages.php:64
actionvx_contact_pre_note_deletedincludes\plugin-pages.php:65
actionvx_contact_pre_trash_leadsincludes\plugin-pages.php:66
actionvx_contact_pre_restore_leadsincludes\plugin-pages.php:67
actionvx_contact_entry_updatedincludes\plugin-pages.php:68
filtervx_callcenter_entries_actionincludes\plugin-pages.php:70
filtervx_callcenter_bulk_actionsincludes\plugin-pages.php:71
actionplugins_loadedintegration-for-contact-form-7-and-pipedrive.php:59
actioncfx_form_submittedintegration-for-contact-form-7-and-pipedrive.php:93
actionvxcf_entry_createdintegration-for-contact-form-7-and-pipedrive.php:94
actionvx_contact_createdintegration-for-contact-form-7-and-pipedrive.php:95
actionvx_callcenter_entry_createdintegration-for-contact-form-7-and-pipedrive.php:96
filterwpcf7_before_send_mailintegration-for-contact-form-7-and-pipedrive.php:98
actionfrm_after_create_entryintegration-for-contact-form-7-and-pipedrive.php:100
actionninja_forms_after_submissionintegration-for-contact-form-7-and-pipedrive.php:101
actionwpforms_process_entry_saveintegration-for-contact-form-7-and-pipedrive.php:102
actionelementor_pro/forms/new_recordintegration-for-contact-form-7-and-pipedrive.php:104
actioninitintegration-for-contact-form-7-and-pipedrive.php:107
filterplugin_row_metawp\crmperks-notices.php:16
filteradmin_footer_textwp\crmperks-notices.php:24
actionadmin_noticeswp\crmperks-notices.php:26
filterplugins_apiwp\crmperks-notices.php:28
Maintenance & Trust

Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 22, 2026
PHP min version5.3
Downloads28K

Community Trust

Rating100/100
Number of ratings26
Active installs1K
Alternatives

Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Alternatives

No alternatives data available yet.

Developer Profile

Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Developer Profile

CRM Perks

32 plugins · 105K total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
339 days
View full developer profile
Detection Fingerprints

How We Detect Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/integration-for-contact-form-7-and-pipedrive/css/style.css/wp-content/plugins/integration-for-contact-form-7-and-pipedrive/js/pipedrive.js
Script Paths
/wp-content/plugins/integration-for-contact-form-7-and-pipedrive/js/pipedrive.js
Version Parameters
integration-for-contact-form-7-and-pipedrive/style.css?ver=integration-for-contact-form-7-and-pipedrive/js/pipedrive.js?ver=

HTML / DOM Fingerprints

CSS Classes
crmperks-pro-upgrade-notice
HTML Comments
plugin api
Data Attributes
data-vxcf-pipedrive-options
JS Globals
vxcf_pipedrive_obj
FAQ

Frequently Asked Questions about Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms