
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Security & Risk Analysis
wordpress.org/plugins/integration-for-contact-form-7-and-pipedriveSend Contact Form 7, WPForms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to Pipedrive.
Is Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Safe to Use in 2026?
Generally Safe
Score 93/100Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The plugin 'integration-for-contact-form-7-and-pipedrive' version 1.2.5 exhibits a mixed security posture. On one hand, the static analysis reveals a promising lack of direct entry points like AJAX handlers, REST API routes, and shortcodes that are unprotected by authentication. This suggests a relatively contained attack surface. Furthermore, the presence of a good percentage of prepared statements for SQL queries and a decent rate of output escaping are positive indicators of secure coding practices. However, the vulnerability history is a significant concern. With three known CVEs, including a past critical vulnerability and two medium severity issues, the plugin has a track record of security flaws. The types of past vulnerabilities (Deserialization, CSRF, XSS) indicate potential for serious compromise if similar issues are present or reoccur.
While the current static analysis shows no critical or high severity taint flows and a low number of file operations and external HTTP requests, the historical vulnerability data cannot be ignored. The past critical vulnerability and the presence of bundled libraries (Select2) which might be outdated or vulnerable warrant careful consideration. The plugin shows efforts towards security with nonce and capability checks, but the persistent occurrence of security flaws in its history is a red flag. The plugin's overall security is therefore tempered by its past performance, suggesting that users should remain vigilant and ensure they are always running the latest patched version, though currently there are no unpatched CVEs.
Key Concerns
- History of critical vulnerability
- History of medium vulnerabilities
- Bundled libraries (Select2)
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.2.3 - Unauthenticated PHP Object Injection via verify_field_val Function
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.2.0 - Cross-Site Request Forgery
CRM Perks - Various Plugins (Various Versions) - Reflected Cross-Site Scripting
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Release Timeline
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Attack Surface
WordPress Hooks 39
Maintenance & Trust
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Maintenance & Trust
Maintenance Signals
Community Trust
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Alternatives
No alternatives data available yet.
Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms Developer Profile
32 plugins · 105K total installs
How We Detect Integration for Pipedrive and Contact Form 7, WPForms, Elementor, Ninja Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/integration-for-contact-form-7-and-pipedrive/css/style.css/wp-content/plugins/integration-for-contact-form-7-and-pipedrive/js/pipedrive.js/wp-content/plugins/integration-for-contact-form-7-and-pipedrive/js/pipedrive.jsintegration-for-contact-form-7-and-pipedrive/style.css?ver=integration-for-contact-form-7-and-pipedrive/js/pipedrive.js?ver=HTML / DOM Fingerprints
crmperks-pro-upgrade-noticeplugin apidata-vxcf-pipedrive-optionsvxcf_pipedrive_obj